cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
787
Views
0
Helpful
3
Replies

Site to Site VPN Tunnel Time-out

w-asaadmin
Level 1
Level 1

The site to site vpn tunnel between the ASA 5510 and ASA 5505 loses connection after more 24 hours of inactivity. However, once I ping the inside address of the ASA 5505 from the ASA 5510 side of the tunnel, the VPN tunnel wakes and continue to work.

I have changed the Crypto isakmp policy

life time to none, but it does not help.

Please help!

3 Replies 3

1cmerchant
Level 1
Level 1

This is how the products are designed to work....once the IKE SA's time out the tunnel drops until additional interesting traffic is sent.

The problem is when the remote users return

to their office over the weekend, the vpn

tunnel is down and they are not able to

connect their computers to the HQ computers.

The VPN tunnel can be waken up by

cycling the power of the remote ASA or I ping

its inside NIC IP address from the other end

of the tunnel.

Any suggestions? Thank you!

OK, The VPN time-out problem has been found.

It was the bandwidth that causes the problem.

Once we upgraded the bandwidth, the problem had gone.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: