Cisco ASA 5505 IPSEC VPN stops passing traffic

We have a Cisco ASA 5505 running 8.2.(1). It is runnng two site to site VPN's. The VPN' stays up, but after awhile, it will stop passing traffic. If we log into the ASDM, and we logout the VPN session and let it get recreated, it creates the tunnel, and traffic starts passing over it okay. It may pass traffic for a few days, then traffic stops. I have maxed the crypto lifetime size as well:
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 2147483647


Thoughts?
greentriangleAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

max_the_kingCommented:
hi,
well, it may well be a failure in data line connection from your ISP, on either end of the tunnel. Indeed, the tunnel would stay up for a little while if the 2 peers lose communication and eventually drop the tunnel.
You may check internet connection by pinging recursively both the data lines routers or firewall from another point: e.g., you open two command line or use any software to ping recursively the 2 data lines, if you see lost packets and vpn tunnel drop, then you'll be pretty sure that it is not a matter of your firewalls.

hope this helps
max
0
InteraXCommented:
Have you tried enabling IKE keepalives for the tunnels?

tunnel-group <groupname> ipsec-attributes
isakmp keepalive 10

This will send an ISAKMP keepalive message every 10 seconds.

Have you setup idle timeout at one end and not the other? What about max connect time?
0
Marius GunnerudSenior Systems EngineerCommented:
If the issue is not with the service provider, then I would say it looks like you are hitting a bug.  try upgrading to a newer version of the ASA 8.2 version.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.