Solved

Cisco network ASA 5520 & 877 VPN's dropping

Posted on 2011-03-11
9
636 Views
Last Modified: 2012-05-11
Hi,

I have a Cisco ASA 5020 in the head office (5mb leased line) with 7 branch offices using Cisco 877's + 8mb ADSL
Every site experiences several VPN drops throughout the day mostly only for a few seconds - is there any way to combat this.

Traffic is light - Email, web browsing (Through a proxy), RDP session.

Some sites are worse than others but overall none of them are reliable - We have one site using a 2mb fibre to the building leased line and drops occur maybe once every two days which is ok - Is it down to the ADSL quality in these sites or would ios / firmware upgrades help.

Thanks,
0
Comment
Question by:joe90kane
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 
LVL 28

Accepted Solution

by:
asavener earned 500 total points
ID: 35113314
VPN reliability is almost entirely dependent on the reliability of the Internet connectivity.

I would set up an IMCP monitor for the public IPs of the remote sites as well as internal addresses at the remote sites, and see if there's a correlation between packet loss.

0
 
LVL 6

Expert Comment

by:Galtar99
ID: 35113807
Have your service provider perform over night testing on the circuit and check the interface counters of the circuits in question for errors.
0
 
LVL 18

Expert Comment

by:decoleur
ID: 35138746
most VPN connections have an inactivity timeout that will cause a connection to drop if there is no interesting traffic traversing an encrypted tunnel.

you should be able to get an indication in the logs of the VPN endpoints what caused the tunnel to disconnect.

if this is a possible issue you can set up a monitoring solution like asavener mentioned that sends a ping every x minutes to keep the tunnel active.

if you need any help setting this up let us know.

-t
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 28

Expert Comment

by:asavener
ID: 35139008
Have you tried any of the testing we suggested?
0
 
LVL 1

Author Comment

by:joe90kane
ID: 35139045
Thanks for the comments - I setup ping plotter and can see extensive packet lose from both the External & Internal IP at the same time so it must be the provider.

Getting a Lan extension installed next week so should resolve / improve the situation.

0
 
LVL 28

Expert Comment

by:asavener
ID: 35352324
I feel that we helped the poster find an underlying network reliability problem, which affected his VPN.
0
 

Expert Comment

by:Modalot
ID: 35381872
Following an Objection by asavener, and after Moderator review, there seems to be a better  disposition, as recommended by the contributing Expert(s).

Modalot
Community Support Moderator
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
2-Factor authentication VPN for staff and suppliers 6 91
Rdp session freeze periodically in FORTIGATE ssl vpn 2 97
RDP- Windows 7 home Premium to 7 Pro via VPN 10 51
TZ400 2 41
For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question