cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1966
Views
3
Helpful
4
Replies

IPSEC Tunnels always UP

Tauer Drumond
Level 1
Level 1

Hi all,

I've a ASA 5540 and configured a Site-to-Site VPN, but the IPSEC tunnels frequently goes down, and when I ping a remote host, the tunnels go UP.

Is there a way to keep the tunnels always UP?

Thanks

Tauer

4 Replies 4

networker99
Level 1
Level 1

You might be able to enter 0 for the idle timeout however not sure if this is possible. Why not just increase the idle timeout?

Configure isakmp keepalives on both ends...

securityappliance(config)#tunnel-group x.x.x.x ipsec-attributes

securityappliance(config-tunnel-ipsec)isakmp keepalive threshold 15 retry 10

ok... I'll apply.

I post the result

Thanks

Tauer

lrm001c474
Level 1
Level 1

Enable dead peer detection with the following group level command:

isakmp keepalive

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card