Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 

When OSPF is run over PIX/ASA 6.3 or 7.1, the VPN tunnel starts to flap

Core issue

This behavior is observed because, after Open Shortest Path First (OSPF) routes are exchanged and the OSPF table is full, the default route is no longer used to reach the remote peer for VPN.

This problem is caused by Cisco bug ID CSCsc65636.

Resolution

To resolve this issue, configure a static route on the Adaptive Security Appliance (ASA). The static route must indicate that in order to reach the remote peer, the default gateway of the Internet Service Provider (ISP) must be used.

For more information, refer to PIX/ASA 7.x VPN/IPSec OSPF Configuration Example.

1042
Views
0
Helpful
0
Comments