cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
442
Views
0
Helpful
5
Replies

PIX VPN problem when remote peer changes IP

redinarsa
Level 1
Level 1

I have some VPNs between a PIX with static IP and several routers with dynamic IP.

When one of the remote routers changes its IP the PIX keeps the VPN with the old one and it doesn't allow the VPN with the new IP until I manually kill the old one...

Keepalives are activated.

Any help ?

Thank you.

5 Replies 5

palomoj
Level 1
Level 1

If you're using PIX OS 7 or 8 you can utilize the DefaultL2LGroup. Otherwise you can configure the PIX as an EasyVPN server.

I am using the DefaultL2LGroup, the VPN works OK... but when the remote peer changes its IP the PIX doesn't allow the new VPN (with the new peer IP) until I manually "kill" the VPN with the old IP.

Try reducing the sa lifetime.

HTH

Saju

I don't think that solves the problem, I still have to wait until the lifetime expires.

Shouldn't the PIX realice that the old peer is dead and allow the new VPN ?.

The remote router is a Linksys.

Try reducing the sa lifetime.

HTH

Saju