Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

HOWTO: Disable DPD keep-alives on ASA

Hello...

I have an IPSec remote access VPN configuration (ASA 7.1 on 1 end - VPN client v 5.0 on the other end) and I have an issue where the connection is dropping regardless if there is traffic been sent across the tunnel or not!!

The tunnel stays up for different periods of time but at the end it dropps!

I have gather the following error message from the ASA:

ASA-EVOTO#

%PIX|ASA-3-713123: IKE lost contact with remote peer, deleting connection (keepalive type: DPD)

This message indicates that the remote IKE peer did not respond to keep-alives within the expected window of time, so the connection to the IKE peer was terminated.

The message includes the keep-alive mechanism used.

So, Is there a way to disable keep-alives between the VPN Client and the ASA platform ?

What else might resolve this problem

Thanks a lot

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: HOWTO: Disable DPD keep-alives on ASA

Hi,

"isakmp keepalive disable" under the Tunnel Group Configuration.

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1732140

Regards,

Arul

*Pls rate if it helps*

3 REPLIES
Cisco Employee

Re: HOWTO: Disable DPD keep-alives on ASA

Hi,

"isakmp keepalive disable" under the Tunnel Group Configuration.

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html#wp1732140

Regards,

Arul

*Pls rate if it helps*

Community Member

Re: HOWTO: Disable DPD keep-alives on ASA

Thanks a lot men!

it worked!

Community Member

Re: HOWTO: Disable DPD keep-alives on ASA

Hi Arul,

I have a similar problem:

My VPN tunnel ended after 3 hours approximatly, I need to increase to 5 hours.

How can I do it?

Kind regards.

Fabrice

18088
Views
15
Helpful
3
Replies
CreatePlease to create content