Site-to-site VPN Tunnel not rebuilding after internet loss on either end

Unanswered Question
Jan 3rd, 2008


I have two sites which are connected by a site-to-site VPN tunnel.

If either site loses their internet connection (for any reason), the connection doesn't automatically rebuild. The only way I have found to fix the issue is to 'clear crypto session" on the head end.

Anyone have any clue what could be causing this? Pretty standard configuration I thought..

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Danilo Dy Fri, 01/04/2008 - 11:41


What did you see in the log?

You may need to update the IOS. In Router S2S VPN, there is a bug when connection is terminated abruptly - may be present to PIX/ASA as well.

I have similar problem and was fixed by IOS update.



tylerlucas Fri, 01/04/2008 - 12:45

Which logs should I be looking at when this occurs? I'm fairly new to VPNs.

I could recreate the issue after hours and take a peek.

tylerlucas Fri, 01/04/2008 - 12:47

For the record, the head end is on a 2821, and the other end is on an 877.

Danilo Dy Sat, 01/05/2008 - 10:18


Can you post the "show ver" output of both routers?

I can't remember the exact text in the log but it's with "SPI". Cisco solution is to clear the sa.




This Discussion