We help IT Professionals succeed at work.

Dynamic-to-Static L2L IPSec VPN

fyoumb
fyoumb asked
on
Hi,
 
I've implemented a Dynamic to Static Site-to-Site IPSec VPN between a ASA5505 on a vessel and the headquarters. Now, this solution doesn't allow the HQ to initiate the IPsec connection.  
 
In the Vessel network, there is a router behind the ASA5505. I heard that if I want to keep the tunnel up, so that HQ clients can initiate traffic to remote clients through the tunnel, I'd need to run IP SLA icmp probes on the router behind the ASA.
 
Could someone explain how to implement it?
 
Thanks for your help.

Frank
Comment
Watch Question

Network Architect
Commented:
Not a problem.

ip sla 10
 icmp-echo x.x.x.x
 timeout 1000
 threshold 750
 frequency 30
ip sla schedule 10 life forever start-time now

Just replace x.x.x.x with the IP address at the HQ that you want to ping.

Author

Commented:
Thanks!!!

Frank