Solved

Cisco network ASA 5520 & 877 VPN's dropping

Posted on 2011-03-11
9
635 Views
Last Modified: 2012-05-11
Hi,

I have a Cisco ASA 5020 in the head office (5mb leased line) with 7 branch offices using Cisco 877's + 8mb ADSL
Every site experiences several VPN drops throughout the day mostly only for a few seconds - is there any way to combat this.

Traffic is light - Email, web browsing (Through a proxy), RDP session.

Some sites are worse than others but overall none of them are reliable - We have one site using a 2mb fibre to the building leased line and drops occur maybe once every two days which is ok - Is it down to the ADSL quality in these sites or would ios / firmware upgrades help.

Thanks,
0
Comment
Question by:joe90kane
9 Comments
 
LVL 28

Accepted Solution

by:
asavener earned 500 total points
ID: 35113314
VPN reliability is almost entirely dependent on the reliability of the Internet connectivity.

I would set up an IMCP monitor for the public IPs of the remote sites as well as internal addresses at the remote sites, and see if there's a correlation between packet loss.

0
 
LVL 6

Expert Comment

by:Galtar99
ID: 35113807
Have your service provider perform over night testing on the circuit and check the interface counters of the circuits in question for errors.
0
 
LVL 18

Expert Comment

by:decoleur
ID: 35138746
most VPN connections have an inactivity timeout that will cause a connection to drop if there is no interesting traffic traversing an encrypted tunnel.

you should be able to get an indication in the logs of the VPN endpoints what caused the tunnel to disconnect.

if this is a possible issue you can set up a monitoring solution like asavener mentioned that sends a ping every x minutes to keep the tunnel active.

if you need any help setting this up let us know.

-t
0
Don't miss ATEN at NAB Show April 24-27!

Visit ATEN at NAB Show to learn how our "Seamlessly Entertaining" solutions deliver fast, precise video streaming without delays for the broadcasting and media environment. ATEN will showcase its 16x16 Modular Matrix Switch (VM1600) and KVM Over IP Solution (KE6900 series).

 
LVL 28

Expert Comment

by:asavener
ID: 35139008
Have you tried any of the testing we suggested?
0
 
LVL 1

Author Comment

by:joe90kane
ID: 35139045
Thanks for the comments - I setup ping plotter and can see extensive packet lose from both the External & Internal IP at the same time so it must be the provider.

Getting a Lan extension installed next week so should resolve / improve the situation.

0
 
LVL 28

Expert Comment

by:asavener
ID: 35352324
I feel that we helped the poster find an underlying network reliability problem, which affected his VPN.
0
 

Expert Comment

by:Modalot
ID: 35381872
Following an Objection by asavener, and after Moderator review, there seems to be a better  disposition, as recommended by the contributing Expert(s).

Modalot
Community Support Moderator
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VPN between Juniper ssg140 (Static IP) to ASA 5500 (Dynamic IP) 23 43
Resource timeout across a VPN 9 24
asp Google Map 2 55
SSL-VPN Solution 8 15
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question