cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
626
Views
0
Helpful
14
Replies

keepalives to reestablish a dynamic to static tunnel?

ed-rucker
Level 1
Level 1

Hi All,

I have a dynamic to static pix 501 to pix 501 os 6.3 configuration. I would like to use keepalives to re-establish the tunnel in case the tunnel goes down. Can this be done?

1 Accepted Solution

Accepted Solutions

Theres a workaround for everything, you could have the pix at the far end use a local ntp or syslog server, this traffic would bring the tunnel up as long as it was defined as interesting.

View solution in original post

14 Replies 14

acomiskey
Level 10
Level 10

You can use dead peer detection to ensure the tunnel doesn't go down...but I don't think that will bring it back up if it goes down.

isakmp keepalive 10

I've tried this (isakmp keepalive 10), to no avail. Thanks though.

That doesn't keep the tunnel from going down? Or are you just saying it doesn't bring it back up?

it doesn't bring it back up. i'm trying to prepare for the unavoidable power or internet outage that would bring the connection down. i would like the static location to reconnect without effort from the customer on that end. :)

Theres a workaround for everything, you could have the pix at the far end use a local ntp or syslog server, this traffic would bring the tunnel up as long as it was defined as interesting.

that's a good idea. a ping will bring it up. some type of ping utility would also work. i was just looking for a solution on the firewall.

unfortunately the way this has worked out, the static pix is at the remote site. that could be changed but it would be easier to work around it.

Thanks.

sorry, i'm kinda slow. a syslog service on the remote computer with the main office (dynamic pic) logging to the remote syslog should work. Think?

Ya, same difference. As long as the computer has data to send. I was confused before which end was dynamic. What I should have said, since your main end is dynamic, is to have your pix or a computer syslog or ntp to something at the remote site.

no reason you would have known, that would be the logical way. thanks again :)

palomoj
Level 1
Level 1

EasyVPN was built for this - dynamic IP remote VPN endpoints to static head end.

Why involve more points of failure to the mix when you can have the firewalls take care of the tunnel.

Just my 2cents.

palomoj,

Not sure if it matters but in his case the head end firewall was dynamic. Would that still work?

Which ever site has the static can be configured as the EasyVPN server and the dynamic as the EasyVPN client.

Hi,

Correct me if i'm wrong, but I thought the pix 501 would not act as an easy vpn server, only a client.

You can configure 501 for server or client