?
Solved

Cisco VPN Tunnel Drops every 60 secs

Posted on 2014-07-29
2
Medium Priority
?
343 Views
Last Modified: 2014-10-15
Hi,

I have a site to site VPN between a ASA 5520 and a 2801.  The connection has been setup for many
years and I have never had any problems.

However over the last few days the VPN Tunnel resets every 60 Secs causing a small "reconnection pause"
between subnets.  This happens even with a constant ping from both ends causing a "Request Timed Out"

The IKE Rekey is set to 28800, the idle Timeout is 30 Mins and the IPsec Rekey is 3600 secs.

I have tried deleting and recreating the tunnel and its stills drops and restarts every 60 secs.

Other tunnels stay up without any problems.

I'm guessing it's a mismatch in a ACL but wondered if there was a easier way to find out which one.

Can some give me a few areas to check.

Thank you in advance.
0
Comment
Question by:Mongo Peck
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 97

Assisted Solution

by:Experienced Member
Experienced Member earned 1000 total points
ID: 40228157
Perhaps try the following:

Make backups of the VPN router configuration files.

Then do hard resets of the modems and the VPN routers. Config the modems if need be, and restore the VPN configs.

See if a complete reset clears the problem.
0
 
LVL 9

Accepted Solution

by:
David Piniella earned 1000 total points
ID: 40232541
Check your logs and see which side is closing or dropping the connection.

The cisco vpn troubleshooting commands may help if you think it's ACLs, http://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html but I would check your logs to see more before doing debugs.
0

Featured Post

Four New Appliances. Same Industry-leading Speeds.

But don't take it from us.  The Firebox M370 is Miercom tested and Miercom approved, outperforming its competitors for stateless and stateful traffic throughput scenarios.  Learn more about the M370, M470, M570 and M670 and find the right solution for your organization today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month12 days, 11 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question