cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
653
Views
0
Helpful
5
Replies

asa 5520 - iphones are disconnected after a certain time

s.fasel
Level 1
Level 1

Hi,

few people of our university connect with their iPhone (protocol IPSec) to our asa (version 8.0(4)). The VPN connection starts correctly and they can use their iphone without problem. But after about 57min and 33s, all iPhones are disconnected from the ASA (IKE error ?):

Group = yyyy, Username = xxxx, IP = 134.21.xx.xx, QM FSM error (P2 struct &0xce84ccf0, mess id 0xe2ee3d2d)!

Group = yyyy, Username = xxxx, IP = 134.21.xx.xx, Removing peer from peer table failed, no match!up = yyyy, Username = xxxx, IP = 134.21.xx.xx, construct_ipsec_delete(): No SPI to identify Phase 2 SA!

Group = yyyy, Username = xxxx, IP = 134.21.xx.xx, Session disconnected. Session Type: IPsec, Duration: 0h:57m:33s, Bytes xmt: 55592, Bytes rcv: 32342, Reason: Phase 2 Error

someone knows this problem?

Thank you for your help

Sam

5 Replies 5

mvsheik123
Level 7
Level 7

Hi,

Try to remove the 'inspect h323 / inspect sip based on the application the IP phones use. It might help.

Thank you

MS

Hi,

thank you for the answer, but I removed the inspect h323/sip and the problem is always the same.

An another idea?

thank you

Hi,

It might be something to do with VPN idle time like 1Hr. you might have checked it but just wanted to make sure. VPN users log in using laptop than IPhone shows the same behaviour?

MS

Hi,

my idle timeout is 60min and the maximum connect time is unlimited. Only iPhones are disconnect after 57min 33s, but all iphones. We have another clients(WindowsXP/Vista/MacOSX/Linux) and they are no problem.

I have put in attachement the details about iPhone connection, 20 seconds before its disconnection.

Thank you

Hi,

Assuing NAC is doing nothing here, I would test this with different encryption policy than AES for IPsec.

MS

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: