cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
413
Views
0
Helpful
2
Replies

VPN from IoS Router over ISDN

i-kendall
Level 1
Level 1

I have a customer who wants to have a router on one site, with ISDN Internet access, and use this to connect to a central site using IPSec/VPN. Are there any pointers to what I configure in the dialer-list to only dial when there is 'real' traffic, and not have it permanently connected due to the IPSec/IKE etc. maintaining a connection to the central site.

2 Replies 2

r-simpson
Level 3
Level 3

Can’t you just configure your radius idle timer to whatever you need (use ‘show caller timeout’ to verify). Define your interesting traffic to bring up the dialer and the tunnel will teardown when inactive based on the timer. Don’t use keepalives on your VPN or the tunnel/dialer will stay up forever.

m.lestoquoy
Level 1
Level 1

If you talk about the IKE keepalive, I may have a workaround for you.

I've not tried, but I heard it from a cisco guy.

You cannot disable the IKE keepalive but you can distinguish them from another IKE trafic because the source address is 0.0.0.0

So, if your dialer-list exclude this trafic, your line will not go up.