[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Cisco VPN Drop

Posted on 2011-03-17
4
Medium Priority
?
717 Views
Last Modified: 2012-06-21
I have a site to site VPN between an ASA5520 and a PIX515E.

Recently, this VPN has started to drop. This is seemingly at random intervals, but it is always during the evening/night - never during the working day.

The tunnel drops for anywhere between 15-40 minutes before coming back up again with no config changes having been made.

While the VPN is down I am still able to access both the ASA and the PIX using the remote VPN client, as well as non-vpn accessible resources (i.e. websites) behind both devices.

I have some syslog captures from both ends during the issue. The entries specific to the VPN are detailed in the attached file (the trap logging is set to Error). VPN-Issue.txt
0
Comment
Question by:ccfcfc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 14

Expert Comment

by:SIM50
ID: 35158799
It could be a connection issue between two sites. xx.xx.xx.34 didn't respond for 90 seconds to ASA's query packets and ASA assumed the other side is inactive and tore down the connection. Try to run a continuous ping and see if there are any packet losses.
0
 

Accepted Solution

by:
ccfcfc earned 0 total points
ID: 35429198
I'm not sure why it would have made a difference, but we had some L2L VPN configs still in place for sites that were no longer connected.

I did a clean-up to remove the configs for all VPNs no longer in use and we haven't had the problem happen again since.
0
 
LVL 33

Expert Comment

by:digitap
ID: 35783908
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question