PIX 501 site-to-site tunnels?

Unanswered Question
Jul 1st, 2010

I have a remote site that is currently setup using a PIX 501 which is setup on a cable modem. That PIX connects back to two of my main sites using a VPN tunnel. The two main sites have a ASA5505, and a ASA5510, one has a 10MB fiber connection the or three T1s trunked together.

Here is the problem. For some reason the PIX 501 keeps dropping the tunnel with the ASA5505. And until I log in and do a clear crypto isakmp sa, the tunnel with that ASA won't come back up so traffic can be sent over it. The ASA5510 site has no problem though.

I examined the connection and it looks like there are some packets being dropped right before the VPN tunnel goes down so I'm guessing some ISP problems with the PIX501 site. But why does the ASA5510 resume its tunnel, and the ASA5505 can't?

Any help would be greatly appreciated. thank you.   

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
mikewillis Tue, 07/06/2010 - 07:59

Had the problem again this morning. It seems as though the ASA's can generate traffic to the PIX, but the PIX refuses to unless I do a clear crypto isakmp sa.

Any wonderful clues or help out there??

Here is some more info..



This Discussion