Solved

CISCO SA540 firewall keep dropping the VPN

Posted on 2016-10-27
4
17 Views
Last Modified: 2016-11-09
hi,

we using a  BELL 1000 DSL modem with a static IP  in the bride mode and setup my Cisco SA540 firewall as router connect to the modem, I setup this firewall a VPN connect to other branch office, it's good for 2 month.

but starting from 2 days ago, everyday it will randomly dropping the VPN 2 -3 times, every time reboot the firewall will connect the VPN again, I check the log file it keep saying like bottom, any idea? is that mean my IP in use or branch IP in use?
Thu Oct 27 16:03:53 2016 (GMT -0400): [Cisco] [IKE] ERROR:  failed to bind (Address already in use).
0
Comment
Question by:Simon Chen
  • 3
4 Comments
 
LVL 45

Expert Comment

by:Craig Beck
ID: 41864739
That's a problem at the firewall that logged the error. Is there something else using the same source port?
0
 

Assisted Solution

by:Simon Chen
Simon Chen earned 0 total points
ID: 41868842
now I change the firewall to another one, it's same model, I keep it as spare. and now the VPN seems no dropping, but branch office user thought terminal server  connect to our head office will randomly get encryption error and kick out. but after connect back, all the program still in open status. any idea? is that mean the firewall connect still not stable to get the error like that? and the branch users' outlook connect to exchange show the status always connected.

it said:
because of an error in data encryption, this session will end, please try connecting to the remote computer again.
0
 

Accepted Solution

by:
Simon Chen earned 0 total points
ID: 41874783
it maybe cause by the internal network issue cause the firewall drop down. after I rewire the branch office network with a new switch, then I changed back the first firewall, so far already 2 days no drop .hopefully it's just the internal network cause the issue.
0
 

Author Closing Comment

by:Simon Chen
ID: 41880261
I figure out the issue by  myselft
0

Featured Post

Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question