cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
269
Views
0
Helpful
1
Replies

Two 3015 Concentrators behind CSS

msrohman
Level 1
Level 1

Hello all,

I have the following scenario currently in production:

VPNClient---Internet---CSS--2VPNConcentrators

The CSS is 11500 with ver 6.10 .

The Cisco VPN clients are connecting with NAT-T IPSec (UDP 4500). The VPN tunnels are built without a problem. However, the VPN tunnels do not stay built much longer then several hours. If I constantly send 'ping'/ICMP traffic over the tunnel, it will stay up for days.

I have DPD/IKE keepalives enabled. Even with IKE keepalives configured, the tunnels still drop. The VPN Concentrators indicate that they have 'Lose Contact' with the VPN client. The VPN Client will then rebuild the tunnel and stay built for approximately 3-4-5 hours. I attached the config file.

Should the flows always be active for this type of traffic to pass? Maybe I should set the flow for UDP/4500 to permanent?

I'm sort of new to CSS administration. Let me know if anyone has any ideas.

Thanks,

Mike

1 Reply 1

a-vazquez
Level 6
Level 6

Yes, the flow should always be active for the traffic to pass.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: