Solved

site to site tunnel not autostarting

Posted on 2016-11-10
5
80 Views
Last Modified: 2016-11-20
hi all,
i have a site to site issue where, whenever the dsl line goes down and comes back online, my site to site tunnel does not get re established automatically.  i had to reboot the asa5506 and ping a device at the other end then, then the tunnel re establishes.
0
Comment
Question by:mwauki
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 16

Expert Comment

by:max_the_king
ID: 41881952
Hi,
i believe that in your case rebooting ASA is useless ...
should the tunnel get orphan and need to renegotiate parameters with the other end, you might want to issue
clear crypto isakmp sa

but you probably just need to wait for interesting traffic to come up (i.e. pinging some device).

I guess vpn does not come up automatically because DSL data line still experimenting problems: by the time you wait for asa to reboot it may well be that data line gets more stable.

hope this helps
max
0
 

Author Comment

by:mwauki
ID: 41881986
LVL, thanks!

your are right rebooting is useless... but in this case, after 4hrs since the dsl stabalized, tunnel is still down.  Even pinging a device from each site does not seem to bring the tunnel back up hence the asa reboot.
0
 
LVL 16

Accepted Solution

by:
max_the_king earned 250 total points
ID: 41882010
before rebooting, you should take note of:
sh isakmp sa
and see in which state It is.

then you should run
debug crypto isakmp
debug crypto ipsec

and see what happens on console.

max
0
 
LVL 14

Assisted Solution

by:SIM50
SIM50 earned 250 total points
ID: 41882117
I would also enable DPD if it is not enabled.
0
 

Author Closing Comment

by:mwauki
ID: 41894847
much appreciated...
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
This article is a collection of issues that people face from time to time and possible solutions to those issues. I hope you enjoy reading it.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question