Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA 5510 TO IOS ROUTER VPN CONNECTION LOST

We have ASA 5510 8.2(1) and IOS 1841 12.4(15)T1 configured at the ASA with a fixed Internet address and at the 1841 a Static/Dynamic Address. VPN IKE/IPsec tunnel works fine, but to cross traffic sessiones must be present such as ping or any other service so IPSec generete the SA. Rekey is set to 3600 secs, rekey data to 4608000, Idle time-out 30 min

To avoid having to set a dummy traffic between both local/remote nets such as NTP or SNMP, how is possible to enable longer SA?

1 REPLY

Re: ASA 5510 TO IOS ROUTER VPN CONNECTION LOST

Try enabling ISAKMP keepalives. It's on by default on the ASA, but you need to add it on the router.

crypto isakmp keepalive 15 15

Hope it helps.

186
Views
0
Helpful
1
Replies