Solved

Cisco IPSec VPN Client Session gets disconnected at randon times from remote ASA5505

Posted on 2011-03-08
3
6,829 Views
Last Modified: 2012-05-11
We have a number of users connecting / terminatiing Cisco IPSec VPN Client sessions onto a Cisco ASA5505  appliance.

The users are using a variation of Client OS, XP, Vista etc and different versions of the Cisco IPSec VPN Client. What is ahppening is, the clients are getting disconnected from the ASA at randon, sometimes after 5 minutes, 15 minutes even 7 hours. The logs off the Cisco VPN Client show the below,

Cisco Systems VPN Client Version 5.0.05.0290
Copyright (C) 1998-2009 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 6.1.7600
7      10:08:25.162  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
8      10:08:26.176  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
9      10:08:27.190  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
10     10:08:28.204  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
11     10:08:29.218  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CheckUpVASettings: Found IPADDR entry addr=10.4.9.189, error 0
12     10:08:30.232  03/08/11  Sev=Warning/2 CVPND/0xA3400015
Error with call to IpHlpApi.DLL: CleanUpVASettings: Was able to delete all VA settings after all, error 0
13     10:08:31.043  03/08/11  Sev=Warning/2 IKE/0xA3000067
Received an IPC message during invalid state (IKE_MAIN:512)

Any feedback would be great...
0
Comment
Question by:lanbase
  • 2
3 Comments
 
LVL 6

Expert Comment

by:alienXeno
ID: 35081409
The problem might be with the IP pool assignment either through ASA, Radius server, DHCP server etc.
 Use the debug crypto command in order to verify that the netmask and IP addresses are correct. Also, verify that the pool does not include the network address and the broadcast address.
0
 

Accepted Solution

by:
lanbase earned 0 total points
ID: 35082009
Hi, thanks for the information. That's a very good point. However, just to let everyone know. I found out what the problem was. It was a setting on the ASA itself. You have to enable nat traversal for VPN traffic as the ASA needs to know that the incomming packets have already been natted. For example,

crypto isakmp nat-traversal

This did the trick. Prior to this client IPSec VPN sessions were getting timed out at random even after 7 hours or so. The client software versions varied and were Cisco/Non Cisco ones.

Hope that helps :)
0
 

Author Closing Comment

by:lanbase
ID: 35126170
Solution found after my own research and testing
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now