cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
427
Views
0
Helpful
1
Replies

ASA 5510 TO IOS ROUTER VPN CONNECTION LOST

edavila
Level 1
Level 1

We have ASA 5510 8.2(1) and IOS 1841 12.4(15)T1 configured at the ASA with a fixed Internet address and at the 1841 a Static/Dynamic Address. VPN IKE/IPsec tunnel works fine, but to cross traffic sessiones must be present such as ping or any other service so IPSec generete the SA. Rekey is set to 3600 secs, rekey data to 4608000, Idle time-out 30 min

To avoid having to set a dummy traffic between both local/remote nets such as NTP or SNMP, how is possible to enable longer SA?

1 Reply 1

Collin Clark
VIP Alumni
VIP Alumni

Try enabling ISAKMP keepalives. It's on by default on the ASA, but you need to add it on the router.

crypto isakmp keepalive 15 15

Hope it helps.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card