ort11
asked on
PIX 515e 7.1(1) Tunnels Dropping at about 31 mins %PIX-4-113019
I have some tunnels on the firewall that are coming down if there is no interesting traffic. They are all coming down right around 31m:3xs. I can't seem to find the timeout issue here and would like to keep the tunnels up if possible.
%PIX-4-113019: Group = <group-ip-address>, Username = <Group-ip-address>, IP = <Group-ip-address>, Session disconnected. Session Type: IPSecLAN2LAN, Duration: 0h:31m:43s, Bytes xmt: 60, Bytes rct
Thanks in advance
%PIX-4-113019: Group = <group-ip-address>, Username = <Group-ip-address>, IP = <Group-ip-address>, Session disconnected. Session Type: IPSecLAN2LAN, Duration: 0h:31m:43s, Bytes xmt: 60, Bytes rct
Thanks in advance
ASKER
Ok, is 2700 the max on the lifetime?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Please do not stop this thread. We are still having an issue and would like to keep this open. Thanks
If no response is received to LRMoores last post to you or an update on the current position is not posted I will be putting this back in the queue on my next round of cleanups which will be next week.
Thanks
Keith
Thanks
Keith
This is by design. IPSEC tunnels are dynamic and depend on interesting traffic. Setup a periodic (like every 15 minutes) ping on a cron job or something from one workstation to something on the other side.
You can adjust the security association lifetime:
>crypto map mymap 10 set security-association lifetime seconds 2700 <== 45 minutes