cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
450
Views
0
Helpful
2
Replies

site-2-site VPN goes down

bapatsubodh
Level 1
Level 1

Hi,

We have configured Site-to-site VPN from 1841 to partner  VPN head end device over internet. It works fine but suddenly tunnel goes down fro some unknown reason and comes up without changeing any configuration. Internet link utilization is also well within limit.

We have configured crypto isakmp lifetime as 3600.  Changeing it to 600 will cause isakmp parameters to be refreshed every 10 minutes, will it help?

I didnt get chance to see crypto isakmp sa status "QM_IDLE" or not.

Any experience for VPN tunnel going down over internet while all other internet activity is working normally.

Please share the experience.

Thanks in advance.

Subodh

2 Replies 2

aabhatia
Level 1
Level 1

plz check if the crypto acl on both sites are mirror copy of each other

disable keepalives using command

config t

tunnel-group  ipsec-attributes 
isakmp keepalive disable

check output of
sh crypto isa sa
sh crypto ipsec sa when tunnel goes down
also check following debugs

debug cry isa 255
debug cry ipsec 255

Hi,

Thanks AartiBhatia for you reply.

Router 1841 is not supporting the commands which you recomend any alternative commands?

Thanks

Subodh