11-24-2011 12:16 AM
Hi all,
I currently configured a site-to-site vpn connection in one of our client.
Configuration is fine and site-to-site connection is working properly.
We noticed that when the tunnel is idle the site-to-site connection between these two branches is disconnected.
We need to ping the other site in order to re-establish the connection and perform a continuous ping in order to keep the tunnel active.
I would like to ask if there is a way to keep the tunnel active even though there are no activity running on both sites and even without pinging continuously.
Please help..
Thanks,
11-24-2011 03:03 AM
https://supportforums.cisco.com/message/3494880#3494880
Please read this link might helpfull full for you.
Thanks
Ajay
11-24-2011 05:36 PM
Hi Ajay,
Thanks for your response, I really appreciate it.
By the way, I would like to ask if I need to disable IKE keepalive and configure the maximum amount of time for VPN connections on both the ASA on both site.
Thanks
11-24-2011 11:09 PM
If you configure ISAKMP keepalives, it helps prevent sporadically dropped LAN-to-LAN or Remote Access VPN, which includes VPN clients, tunnels and the tunnels that are dropped after a period of inactivity.
Please configure the value for iskmp and rest of the steps. We do disable it when its for vpn client which is behind the firewall.
Thanks
Ajay
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide