cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
702
Views
0
Helpful
6
Replies

problems with applications over vpn ipsec site-to-site

gdspa
Level 1
Level 1

Hi all,

I have some problems with some applications as Xcics and Citrix when client and server are connected through a vpn site-to-site. Clients don't seem to have any problem to connect to the server, but after a period of time, they disconnect even if users are working. Session is not closed correctly on server and stay hung, so users can't connect if the administrator doesn't close the session on the server. Some vpns pass through a Pix515E, others pass through a fwsm and an ASA5510. Does anyone knows something about this issue?

6 Replies 6

Farrukh Haroon
VIP Alumni
VIP Alumni

Have you enabled isakmp keepalives?

Regards

Farrukh

Yes, and I have a software to monitor the connections which sends a ping every 1 minute. Disconnections happen when users are working, not after a period of inactivity.

ssandifer
Level 1
Level 1

Try increasing theses values..

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00

I have controlled with ASDM.Values you indicate are unchecked on my firewall. ASDM guide says "unchecking the check

boxes means there is no timeout value", so the problem is not caused by timeouts, is it?

I resolved the problem configuring connection timeout = 2 hours.

gdspa
Level 1
Level 1

problem solved, see my post of 29-apr-2009

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card