Is there any way to initiate phase 2 without sending data from an inside workstation.
Once the tunnels are up they are good to go unless they drop for an unforseen reason or if the SA's reset. The problem is that there isn't much traffic sourcing at the remote site to bring the tunnels back up if the drop however, the hub site needs to be able to reach out and touch the remote sites.
Remotes sites are configured with a static cryto map set to orginate-only and has two peers defined. The hub site is using a dynamic crypto map.
Thanks for any tips.
A way around this is to have a machine on the remote end or the remote pix itself use a local syslog server, ntp server etc. This traffic would bring up the tunnel without user intervention.