Solved

Cisco VPN Tunnel Drops every 60 secs

Posted on 2014-07-29
2
323 Views
Last Modified: 2014-10-15
Hi,

I have a site to site VPN between a ASA 5520 and a 2801.  The connection has been setup for many
years and I have never had any problems.

However over the last few days the VPN Tunnel resets every 60 Secs causing a small "reconnection pause"
between subnets.  This happens even with a constant ping from both ends causing a "Request Timed Out"

The IKE Rekey is set to 28800, the idle Timeout is 30 Mins and the IPsec Rekey is 3600 secs.

I have tried deleting and recreating the tunnel and its stills drops and restarts every 60 secs.

Other tunnels stay up without any problems.

I'm guessing it's a mismatch in a ACL but wondered if there was a easier way to find out which one.

Can some give me a few areas to check.

Thank you in advance.
0
Comment
Question by:Mongo Peck
2 Comments
 
LVL 90

Assisted Solution

by:John Hurst
John Hurst earned 250 total points
ID: 40228157
Perhaps try the following:

Make backups of the VPN router configuration files.

Then do hard resets of the modems and the VPN routers. Config the modems if need be, and restore the VPN configs.

See if a complete reset clears the problem.
0
 
LVL 9

Accepted Solution

by:
David Piniella earned 250 total points
ID: 40232541
Check your logs and see which side is closing or dropping the connection.

The cisco vpn troubleshooting commands may help if you think it's ACLs, http://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html but I would check your logs to see more before doing debugs.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

This is about downgrading PIX Version 8.0(4) & ASDM 6.1(5) to PIX 7.2(4) and ASDM 5.2(4) but with only 64MB RAM and 16MB flash. Background: You have a Cisco Pix 515E which was running on PIX 7.2(4) and its supporting ASDM 5.2(4) without any i…
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now