Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

IPSEC unresponsive for unknown reason.

Hello all,

I have a handfull of IPSEC Tunnels that randomly become unresponsive. I have not been successfull in gathering any good information as to why. When I look at the debug logs, i see no traffic going up or down the tunnel. The tunnel is said to be connected according to ASDM. The only thing I can do at this point is to logout the tunnel through the ASDM and as soon as trafiic is initiated, the tunnel builds just fine. Any suggestions??? As far as I know, most of the remote firewalls are Checkpoints. Thank you.

4 REPLIES
Community Member

Re: IPSEC unresponsive for unknown reason.

Try to unconfigue and reconfigure the tunnel.A common configuration mistake is to use the same ACL for nat 0 and the static crypto maps.Refer the URL for troubleshooting on PIX

http://www.cisco.com/en/US/customer/tech/tk583/tk372/technologies_tech_note09186a008009448c.shtml#seriesofevents

Community Member

Re: IPSEC unresponsive for unknown reason.

I'm experiencing the same problem with a tunnel between a Pix-515 and an 1811 router. The 1811 is a new addition (where Pix-506's are used on other tunnels) and has been a nightmare.

I upgraded from 7.0.4 to 7.0.6 and that fixed half the issue. I no longer have to "logout" the tunnel to get it working again. Unfortunately not all the problems have been solved as user's tcp sessions are broken several times a day.

What code level are you running?

Community Member

Re: IPSEC unresponsive for unknown reason.

I am having the same problem with 877 router connected to 1841 central router. randomly traffic don't go throught about an hour. Then within a hour it get the traffic back.

During the outage time i can't even ping the lan interface in the central site.

any help

Community Member

Re: IPSEC unresponsive for unknown reason.

I may have found the problem. After comparing all my configurations with the remote administrator we found that our timings are different. His rekey time was much shorter than mine, so we suspect that this could be the cause. We changed our timings to match just Friday, so I will let you know if this appears to fix the issue.

177
Views
0
Helpful
4
Replies
CreatePlease to create content