Solved

site to site tunnel not autostarting

Posted on 2016-11-10
5
58 Views
Last Modified: 2016-11-20
hi all,
i have a site to site issue where, whenever the dsl line goes down and comes back online, my site to site tunnel does not get re established automatically.  i had to reboot the asa5506 and ping a device at the other end then, then the tunnel re establishes.
0
Comment
Question by:mwauki
  • 2
  • 2
5 Comments
 
LVL 15

Expert Comment

by:max_the_king
ID: 41881952
Hi,
i believe that in your case rebooting ASA is useless ...
should the tunnel get orphan and need to renegotiate parameters with the other end, you might want to issue
clear crypto isakmp sa

but you probably just need to wait for interesting traffic to come up (i.e. pinging some device).

I guess vpn does not come up automatically because DSL data line still experimenting problems: by the time you wait for asa to reboot it may well be that data line gets more stable.

hope this helps
max
0
 

Author Comment

by:mwauki
ID: 41881986
LVL, thanks!

your are right rebooting is useless... but in this case, after 4hrs since the dsl stabalized, tunnel is still down.  Even pinging a device from each site does not seem to bring the tunnel back up hence the asa reboot.
0
 
LVL 15

Accepted Solution

by:
max_the_king earned 250 total points
ID: 41882010
before rebooting, you should take note of:
sh isakmp sa
and see in which state It is.

then you should run
debug crypto isakmp
debug crypto ipsec

and see what happens on console.

max
0
 
LVL 13

Assisted Solution

by:SIM50
SIM50 earned 250 total points
ID: 41882117
I would also enable DPD if it is not enabled.
0
 

Author Closing Comment

by:mwauki
ID: 41894847
much appreciated...
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Access point 6 54
Alcatel Lucent OS6450 switch randomly reboots 4 49
Cisco Router / Switch - NAT 10 32
Some help with Network Design 4 22
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now