Solved

site to site tunnel not autostarting

Posted on 2016-11-10
5
64 Views
Last Modified: 2016-11-20
hi all,
i have a site to site issue where, whenever the dsl line goes down and comes back online, my site to site tunnel does not get re established automatically.  i had to reboot the asa5506 and ping a device at the other end then, then the tunnel re establishes.
0
Comment
Question by:mwauki
  • 2
  • 2
5 Comments
 
LVL 16

Expert Comment

by:max_the_king
ID: 41881952
Hi,
i believe that in your case rebooting ASA is useless ...
should the tunnel get orphan and need to renegotiate parameters with the other end, you might want to issue
clear crypto isakmp sa

but you probably just need to wait for interesting traffic to come up (i.e. pinging some device).

I guess vpn does not come up automatically because DSL data line still experimenting problems: by the time you wait for asa to reboot it may well be that data line gets more stable.

hope this helps
max
0
 

Author Comment

by:mwauki
ID: 41881986
LVL, thanks!

your are right rebooting is useless... but in this case, after 4hrs since the dsl stabalized, tunnel is still down.  Even pinging a device from each site does not seem to bring the tunnel back up hence the asa reboot.
0
 
LVL 16

Accepted Solution

by:
max_the_king earned 250 total points
ID: 41882010
before rebooting, you should take note of:
sh isakmp sa
and see in which state It is.

then you should run
debug crypto isakmp
debug crypto ipsec

and see what happens on console.

max
0
 
LVL 14

Assisted Solution

by:SIM50
SIM50 earned 250 total points
ID: 41882117
I would also enable DPD if it is not enabled.
0
 

Author Closing Comment

by:mwauki
ID: 41894847
much appreciated...
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ASA DHCP setup 5 29
Install SSL certificate on Cisco ASA 5506 6 25
How to simulate latency? 5 27
cisco switch 3750E port channel down 11 16
Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question