Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA 5510 tunnel dropping

We have two ASA 5510 firewalls with a tunnel between two sites. The tunnel works without issue until one of the sites experiences a brief outage due to the service provider. The VPN tunnel is not automatically establishing after the outage. It takes a restart of one of the ASA's before it will come back online. How do I get the devices to automatically try to restore the tunnel?



Re: ASA 5510 tunnel dropping


If you configure ISAKMP keepalives, it helps prevent sporadically dropped LAN-to-LAN or Remote Access VPN, which includes VPN clients, tunnels and the tunnels that are dropped after a period of inactivity. This feature lets the tunnel endpoint monitor the continued presence of a remote peer and report its own presence to that peer. If the peer becomes unresponsive, the endpoint removes the connection. In order for ISAKMP keepalives to work, both VPN endpoints must support them.

*Cisco PIX/ASA 7.x and later, for the tunnel group named

securityappliance(config)#tunnel-group ipsec-attributes

securityappliance(config-tunnel-ipsec)#isakmp keepalive threshold 15 retry 10

Hope that helps.

New Member

Re: ASA 5510 tunnel dropping

Thanks for your reply Collin. As it stands, the "isakmp keepalive" command is enabled by default on ASA appliances with 7.2 code. The keepalive command has not been removed from the configuration. Both devices are ASA 5510's with 7.2 software running on them.