1801 Router - Keep having to 'clear crypto'

Unanswered Question
Nov 10th, 2008
User Badges:

We have about 8 Cisco 1801s deployed using broadband and the ezvpn client configuration back to head office. One of our sites keeps experiencing intermittent dropouts of its ADSL interface which we are investigating. However the problem is compounded because when the atm interface comes back up the ipsec tunnel does not. I have to log on to the public address of the router and issue the 'clear crypto ipsec client ezvpn' command. Below is samples of the relevant configuration. Is there a way to force the tunnel to clear down and reconnect if the atm changes state?

crypto ipsec client ezvpn phntvpn

connect auto

group gables key #####

mode network-extension

peer x.x.x.x

username gablesUser password ######

xauth userid mode local

interface ATM0

mtu 1478

no ip address

no ip mroute-cache

no atm ilmi-keepalive

pvc 0/38

encapsulation aal5mux ppp dialer

dialer pool-member 1


dsl operating-mode auto

interface Vlan1

ip address

ip helper-address

ip tcp adjust-mss 1452

no autostate

crypto ipsec client ezvpn phntvpn inside

interface Dialer1

description "ADSL Interface"

ip address x.x.x.x

no ip redirects

no ip unreachables

no ip proxy-arp

encapsulation ppp

dialer pool 1

no cdp enable

ppp authentication chap callin

ppp chap hostname #########

ppp chap password 0 ########

crypto ipsec client ezvpn phntvpn

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
smahbub Fri, 11/14/2008 - 11:16
User Badges:
  • Silver, 250 points or more

Yes, you can force the tunnel to clear down and reconnect if the atm changes state.To specify automatic tunnel control on a Cisco Easy VPN remote device, you need to configure the "crypto ipsec client ezvpn" command and then the "connect auto" subcommand.To disconnect or reset a particular tunnel, you should use the clear crypto ipsec client ezvpn command.


This Discussion