Initiate L2L IPSEC Tunnel on ASA

Unanswered Question
Jul 18th, 2008

Using ASA 5510s for L2L IPSEC tunnels with DSL connections between sites. These tunnels are for backup connectivity if the primary Metro connection goes down. As long as the Metro is up no traffic will flow across the IPSEC tunnels because there is no interesting traffic to initiate the tunnel.

Is there a way other than defining interesting traffic to keep the IPSEC tunnels up at all times?

I've set the VPN idle time out to none which should keep them up after they are initiated. I'd rather not have to pull my Metro connections to force the tunnels up and I don't want to wait for a Metro outage to ensure they are working.


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Marwan ALshawi Sat, 07/19/2008 - 00:58

if u want it up all time

use GRE over IPsec and use a routing protocol between ur VPN peers

in this case u gonna keep ur connection up

but if u have routing over ur metro

becare from makeing a conflect or ur the vpn being the prefered

good luck

rate if helps


This Discussion