Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN 3015 consentrator to Clinet connection lost

Dear All,

I have a problem on a VPN network, I have a VPN 3015 and users using the VPN client. ( both is version 3.6).

The problem is that some 10-20 users losing there conection after a while and need to reconect. The log information on the client is:

123 20:05:22.633 10/17/02 Sev=Info/4 IKE/0x63000013

SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 212.242.88.234

124 20:05:27.633 10/17/02 Sev=Info/6 IKE/0x6300003D

Sending DPD request to 212.242.88.234, seq# = 4003831256

125 20:05:27.633 10/17/02 Sev=Info/4 IKE/0x63000013

SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 212.242.88.234

126 20:05:33.132 10/17/02 Sev=Info/5 IKE/0x63000018

Deleting IPsec SA: (OUTBOUND SPI = 14E329B8 INBOUND SPI = EEE683F8)

127 20:05:33.132 10/17/02 Sev=Info/5 IKE/0x63000018

Deleting IPsec SA: (OUTBOUND SPI = 4DD021E8 INBOUND SPI = FB90DE40)

128 20:05:33.132 10/17/02 Sev=Info/5 IKE/0x63000017

Marking IKE SA for deletion (COOKIES = 728409A9FD9BC72A A3BDED35299E4E7E) reason = DEL_REASON_DONT_NOTIFY_CM

129 20:05:33.132 10/17/02 Sev=Info/4 IKE/0x63000013

SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 212.242.88.234

130 20:05:33.132 10/17/02 Sev=Info/4 CM/0x63100013

Phase 1 SA deleted cause by DEL_REASON_PEER_NOT_RESPONDING. 0 Phase 1 SA currently in the system

131 20:05:33.461 10/17/02 Sev=Info/5 CM/0x63100029

Initializing CVPNDrv

132 20:05:33.461 10/17/02 Sev=Info/4 CM/0x63100031

Resetting TCP connection on port 10000

133 20:05:33.461 10/17/02 Sev=Info/6 CM/0x63100034

Removed local TCP port 1037 for TCP connection.

134 20:05:33.461 10/17/02 Sev=Info/6 CM/0x63100035

Tunnel to headend device vpn.fgnet.dk disconnected: duration: 0 days 0:35:53

135 20:05:33.507 10/17/02 Sev=Info/4 IPSEC/0x63700013

Delete internal key with SPI=0xf883e6ee

136 20:05:33.507 10/17/02 Sev=Info/4 IPSEC/0x6370000C

Key deleted by SPI 0xf883e6ee

137 20:05:33.507 10/17/02 Sev=Info/4 IPSEC/0x63700013

Delete internal key with SPI=0xb829e314

Does any have a Idee of this problem. ?

Best regards

Sore Knudsen

skn@qualitynet.dk

2 REPLIES
New Member

Re: VPN 3015 consentrator to Clinet connection lost

We saw the same problem. The only way around it that we could see was to disable IKE keepalives for the group and then hope that the idle timeout will disconnect those clients that have been rudely dropped but are still listed. This has fixed most of the disconnects we were getting and I haven't had anymore complaints (we get ~25 users connected at any one time). I use it about every day and havew only been disconnected once in the last 2 months.

We figured that the IKE keepalive packets were getting lost or dropped when a dial up client was busy doing other things and had pretty much filled up its pipe. You may want to check the bandwidth on your internet connection as we had to upgrade from a T1 because of the number of Cable/DSL users working from home.

New Member

Re: VPN 3015 consentrator to Clinet connection lost

Thanx for the info

95
Views
0
Helpful
2
Replies