Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPSEC tunnel issues

I have a handful of 871's for SOHO users which started out utilizing an EZVPN tunnel back to an ASA at our headquarters location. That was extremely unstable so it has now been flipped to a static to dynamic mapping in the default L2L tunnel group and I'm see similar results. I've tried isolating the issues with no luck.

I've added an attachment with the error messages I see consistently. It seems as though the ASA 5520 just stops responding.

I've messed with the tcp mss values clearing the df-bit and also tried some of the timers but nothing seems to work.

Sometimes the tunnel stays up for hours other times it drops after 5 minutes. One thing that is consistent is that it drops multiple times per day.

Any assistance would be greatly appreciated.


Re: IPSEC tunnel issues

This document contains the most common solutions to IPsec VPN problems. These solutions come directly from service requests that the Cisco Technical Support have solved. Many of these solutions can be implemented prior to the in-depth troubleshooting of an IPsec VPN connection. As a result, this document is presented as a checklist of common procedures to try before you begin to troubleshoot a connection and call Cisco Technical Support.

New Member

Re: IPSEC tunnel issues

I already resolved the issue but thanks for the information.

New Member

Re: IPSEC tunnel issues

What was the resolution???

I have a 5520 set up with EzVPN and 1841 IOS routers on the remote end that are experiencing the same issues you explain. I have been working with TAC for a while now and they aren't sure how to fix it.