Solved

How can I keep a VPN connection alive in Cisco IOS

Posted on 2011-09-09
7
686 Views
Last Modified: 2012-05-12
Hi Experts,

Here is the problem :
Router A with fixed IP, Router B with dynamic IP
So, according to what I read, only router B can initiate the VPN connection.
When I try to reach Router A from Router B, the VPN goes up instantly and everything works perfectly.
The problem is that I only need the VPN connection from A to B, and when A needs to communicate, the VPN is down for time out reason and the VPN can be initiated this way.
I though that entering "crypto isakmp keepalive 20 periodic" on Router B will solve the problem but no.

Can you help me please ?
0
Comment
Question by:Galadorn
  • 4
  • 3
7 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36509096
What you could try is  set up NTP and have the router synchronize its clock to the VPN peer. That should keep the tunnel up.
0
 

Author Comment

by:Galadorn
ID: 36509196
How strange it is really that VPN is so easy with a Linksys RV042 and so difficult with a Cisco. In RV042, when you check "Keepalive", the VPN never goes down. There's no equivalent in IOS ?
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
ID: 36509276
You could try: crypto ipsec security-association idle-time 86400

That's the max number of seconds but perhaps that is enough.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 

Author Comment

by:Galadorn
ID: 36527435
It's enough time and a good turn around solution. Thanks.
But I finally managed to initiate VPN from Router A.
Thanks for your help.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36531455
Thx for the points :)

So you got it working? Would you care to tell how you did that? I'm always curious ;)
0
 

Author Comment

by:Galadorn
ID: 36534987
Sure.
Instead of configuring a dynamic crypto map, configure a standard static crypto map as if you had a fixed IP.
When you configure the peer address, use the "set peer <my ddns name here> dynamic" command. I've never realised that you could specify "dynamic" at the end...
This way, the peer is resolved each time a new VPN connection has to be established.

I tried lots of time before but without the "dynamic" keyword I didn't even noticed and of course, it didn't worked this way because the IP address was resolved and directly hardcoded in the router. It was only working until the change of the IP's remote router.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36541342
Cool, haven't used that before (too much focused on static ip's :-~ ).
Thanks for the info!
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Outlook keeps opened file locked 2 56
How to make my old USB printer wireless? 71 159
using BGP Attributes 2 54
Cost effective dual wan w/ qos 5 29
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now