Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PIX 506 to Concentrator connection dropouts


we have setup a PIX 506e to connect to an unknown Cisco concentrator in the US (managed by a third party). The VPN is up and working, however occasionally the VPN drops out and we get the following error:

IPSEC(key_engine): got a queue event...

IPSEC(key_engine_delete_sas): red'd delete notify from ISAKMP

IPSEC(sa_find_prot): invalid protocol on SADB lookup

I'm assuming its a timeout error, so both the PIX and the concentrator have their lifetimes now set to 86400. When this occurs the only way to get the two to reconnect is to reload the PIX.


New Member

Re: PIX 506 to Concentrator connection dropouts

I am really not sure about this problem, but you could try these debug commands to get a better picture on this problem

* debug crypto engine - Shows the traffic that is encrypted.

* debug crypto ipsec - To see the IPSec negotiations of phase 2.

* debug crypto isakmp - To see the ISAKMP negotiations of phase 1.

New Member

Re: PIX 506 to Concentrator connection dropouts

yep, thats how I got the info out that was included in the original post.

I'm going to try to stagger the PIX so that it does a reset every half day, but I shouldnt have to do this.

I should be able to keep the connection permanantly up????

Cisco Employee

Re: PIX 506 to Concentrator connection dropouts

See if enabling ike keepalive would help. Set it on the group for the lan to lan on the concentrator, and enable isakmp keepalive on pix.


New Member

Re: PIX 506 to Concentrator connection dropouts

i have set keepalive on the pix to be 180 seconds and it still dropped out overnight. As I dont control the VPN Concentrator (third party), what has to be set on this??

CreatePlease login to create content