The following is the setup and the problem we have:
* MGCP call agent -- ASA 5510 -- vpn tunnel -- linksys -- MGCP gateway
* VPN tunnel setup is in aggresive mode (initiated as needed from linksys).
* When MGCP call agent is up but the vpn tunnel is still down, MGCP traffic (udp/2427) tried to reach gateway and failed --> this is as expected.
* Next, linksys brings up the vpn tunnel
* Any other IP traffic can go through the tunnel, but not MGCP traffic from call agent to gateway.
* Checked from packet tracer: it passed phase 1 & 2 (checking the flow), it found existing flow and used that flow. Then it stuck there, looks like it didn't know where to go next (no ACL or route checking).
We noticed that the annoying following workaround will make the MGCP goes through.
* shutdown MGCP call agent
* disconnect vpn tunnel from linksys
* system reload the ASA5510
* after ASA5510 is up, linksys initiate the vpn tunnel
* after vpn is up, bring up MGCP call agent
* MGCP traffic goes through the tunnel
It seems like ASA MGCP flow table is not updated if there is status change in VPN tunnel. Any idea how to fix this ?