Solved

Enhanced Easy VPN tunnel establishes and then drops from DSL.

Posted on 2008-10-23
2
930 Views
Last Modified: 2013-12-14
I have an Enhanced Easy VPN server running on a 2801 router at my corporate office.  I am using 851W routers in the field to connect with Easy VPN remote.  This is working great from three locations with cable modems, but when i place an 851W at any of my Bellsouth DSL sites the VPN tunnel establishes connection and stays up for 2-4 minutes and then I lose connectivity.  The VPN light is on on the router at the branch office and it shows as up from the SDM.  And then every hour on the hour for 1 minute the tunnel comes up.  If i ping -t the ip of the remote router from the corporate office with it is up for that 1 minute it will stay up as long as i keep pinging it.  It was up for 12 hours last night and when i ended the ping it was down in just a few minutes.   I am running 12.4 on the 851s.   The funny thing is that i can take this same router with the same config and put it at a cable modem site and the tunnel never fails.
0
Comment
Question by:MBAMike
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 

Accepted Solution

by:
MBAMike earned 0 total points
ID: 22787371
I think i may have found a solution to the problem.   I added the lines below to both routers and reset the tunnel. ( i did this initially with SDM which uses dymamic and not periodic by default)

crypto isakmp keepalive 10 periodic

I also found out why the connection would be active every hour.  The "crypto ipsec security-association lifetime" is defaulted to one hour.  I set mine to 2400 which is 20 minutes.  

crypto ipsec security-association lifetime seconds 2400

When i did this the tunnel would become active for a minute or two every 20 minutes.

I also found several posts that suggest this should be set to 24 hours.
crypto ipsec security-association lifetime seconds 86400

I configured the server and remote routers with with SDM and not the command line and i believe this is why the keepalive statements were missing.  

0
 
LVL 9

Expert Comment

by:Press2Esc
ID: 22807991
Interesting....  thanks for the heads up MBA...  P2E
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question