Solved

Cisco IPSec VPN Client Session gets disconnected at randon times from remote ASA5505

Posted on 2011-03-08
3
6,991 Views
Last Modified: 2012-05-11
We have a number of users connecting / terminatiing Cisco IPSec VPN Client sessions onto a Cisco ASA5505  appliance.

The users are using a variation of Client OS, XP, Vista etc and different versions of the Cisco IPSec VPN Client. What is ahppening is, the clients are getting disconnected from the ASA at randon, sometimes after 5 minutes, 15 minutes even 7 hours. The logs off the Cisco VPN Client show the below,

Cisco Systems VPN Client Version 5.0.05.0290
Copyright (C) 1998-2009 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 6.1.7600
7      10:08:25.162  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
8      10:08:26.176  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
9      10:08:27.190  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
10     10:08:28.204  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
11     10:08:29.218  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
12     10:08:30.232  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CleanUpVASettings: Was able to delete all VA settings after all, error 0
13     10:08:31.043  03/08/11  Sev=Warning/2 IKE/0xA3000067
Received an IPC message during invalid state (IKE_MAIN:512)

Any feedback would be great...
0
Comment
Question by:lanbase
  • 2
3 Comments
 
LVL 6

Expert Comment

by:alienXeno
ID: 35081409
The problem might be with the IP pool assignment either through ASA, Radius server, DHCP server etc.
 Use the debug crypto command in order to verify that the netmask and IP addresses are correct. Also, verify that the pool does not include the network address and the broadcast address.
0
 

Accepted Solution

by:
lanbase earned 0 total points
ID: 35082009
Hi, thanks for the information. That's a very good point. However, just to let everyone know. I found out what the problem was. It was a setting on the ASA itself. You have to enable nat traversal for VPN traffic as the ASA needs to know that the incomming packets have already been natted. For example,

crypto isakmp nat-traversal

This did the trick. Prior to this client IPSec VPN sessions were getting timed out at random even after 7 hours or so. The client software versions varied and were Cisco/Non Cisco ones.

Hope that helps :)
0
 

Author Closing Comment

by:lanbase
ID: 35126170
Solution found after my own research and testing
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
syslog id vs. msg 2 29
logging buffered 8 47
How to configure windows DNS (internal) forwarding to bind DNS (external) 3 15
VLAN Overused monitor 4 14
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question