cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
29390
Views
20
Helpful
3
Replies

HOWTO: Disable DPD keep-alives on ASA

glenn.guzman
Level 1
Level 1

Hello...

I have an IPSec remote access VPN configuration (ASA 7.1 on 1 end - VPN client v 5.0 on the other end) and I have an issue where the connection is dropping regardless if there is traffic been sent across the tunnel or not!!

The tunnel stays up for different periods of time but at the end it dropps!

I have gather the following error message from the ASA:

ASA-EVOTO#

%PIX|ASA-3-713123: IKE lost contact with remote peer, deleting connection (keepalive type: DPD)

This message indicates that the remote IKE peer did not respond to keep-alives within the expected window of time, so the connection to the IKE peer was terminated.

The message includes the keep-alive mechanism used.

So, Is there a way to disable keep-alives between the VPN Client and the ASA platform ?

What else might resolve this problem

Thanks a lot

1 Accepted Solution

Accepted Solutions

ajagadee
Cisco Employee
Cisco Employee

Hi,

"isakmp keepalive disable" under the Tunnel Group Configuration.

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1732140

Regards,

Arul

*Pls rate if it helps*

View solution in original post

3 Replies 3

ajagadee
Cisco Employee
Cisco Employee

Hi,

"isakmp keepalive disable" under the Tunnel Group Configuration.

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1732140

Regards,

Arul

*Pls rate if it helps*

Thanks a lot men!

it worked!

Hi Arul,

I have a similar problem:

My VPN tunnel ended after 3 hours approximatly, I need to increase to 5 hours.

How can I do it?

Kind regards.

Fabrice

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: