Solved

Cisco network ASA 5520 & 877 VPN's dropping

Posted on 2011-03-11
9
632 Views
Last Modified: 2012-05-11
Hi,

I have a Cisco ASA 5020 in the head office (5mb leased line) with 7 branch offices using Cisco 877's + 8mb ADSL
Every site experiences several VPN drops throughout the day mostly only for a few seconds - is there any way to combat this.

Traffic is light - Email, web browsing (Through a proxy), RDP session.

Some sites are worse than others but overall none of them are reliable - We have one site using a 2mb fibre to the building leased line and drops occur maybe once every two days which is ok - Is it down to the ADSL quality in these sites or would ios / firmware upgrades help.

Thanks,
0
Comment
Question by:joe90kane
9 Comments
 
LVL 28

Accepted Solution

by:
asavener earned 500 total points
ID: 35113314
VPN reliability is almost entirely dependent on the reliability of the Internet connectivity.

I would set up an IMCP monitor for the public IPs of the remote sites as well as internal addresses at the remote sites, and see if there's a correlation between packet loss.

0
 
LVL 6

Expert Comment

by:Galtar99
ID: 35113807
Have your service provider perform over night testing on the circuit and check the interface counters of the circuits in question for errors.
0
 
LVL 18

Expert Comment

by:decoleur
ID: 35138746
most VPN connections have an inactivity timeout that will cause a connection to drop if there is no interesting traffic traversing an encrypted tunnel.

you should be able to get an indication in the logs of the VPN endpoints what caused the tunnel to disconnect.

if this is a possible issue you can set up a monitoring solution like asavener mentioned that sends a ping every x minutes to keep the tunnel active.

if you need any help setting this up let us know.

-t
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 28

Expert Comment

by:asavener
ID: 35139008
Have you tried any of the testing we suggested?
0
 
LVL 1

Author Comment

by:joe90kane
ID: 35139045
Thanks for the comments - I setup ping plotter and can see extensive packet lose from both the External & Internal IP at the same time so it must be the provider.

Getting a Lan extension installed next week so should resolve / improve the situation.

0
 
LVL 28

Expert Comment

by:asavener
ID: 35352324
I feel that we helped the poster find an underlying network reliability problem, which affected his VPN.
0
 

Expert Comment

by:Modalot
ID: 35381872
Following an Objection by asavener, and after Moderator review, there seems to be a better  disposition, as recommended by the contributing Expert(s).

Modalot
Community Support Moderator
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VOIP Setup through a Watchguard BOVPN 4 81
Setting up a VPN 60 137
Internet Protocol Security question 3 67
IPSec/L2TP 25 25
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question