Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

failback L2L tunnel from failover

I have a router with 2 ISP's with 2 L2L tunnels, if the primary goes down it fails over to the backup VPN tunnel just fine, however when the primary comes back up it tries to create a VPN tunnel but the VPN tunnel on the secondary is working and connected so it does not work. The problem is that because the primary came back up it stops routing through the secondary VPN tunnel and then everything is down until I go in and submit clear crypto sa. Is there a automated way of either failback to the primary or not letting the primary tunnel to come up if the primary interface comes up? Any suggestion would be helpful or if anybody is doing this, please give me some suggestions on how to fix this.

Thank you


Re: failback L2L tunnel from failover

You need to configure DPD between the routers. On IOS, the command is 'crypto isakmp keepalive' and on ASA it's 'isakmp keepalive'. DPD is enabled by default on ASA for Remote Access and L2L tunnels.