12-19-2011 06:41 AM
I am not an expert on VPN tunnels so I am putting this out there to make sure I have covered all my bases. Every so often, sometime every 10 minutes sometimes every 30 minutes, we lose about 8 pings to a remote site that rides a site-to-site VPN tunnel. This tunnel is between two ASA5520's. The SA lifetime is 8 hrs and the traffic volume is at 4608000. My first thought was that it is hitting the traffic volume and causing the tunnels to rebuild. However, if you force the tunnels to rebuild you barely lose a ping or two. I have run out of ideas and the entity providing transport connectivity is annoyed at the idea that I think they caused the problem. Can anyone think of anything that would or could cause this? It started two weeks ago and no configuration had been changed at all. Thanks!
12-19-2011 07:12 AM
what ASA version you are running ?
12-19-2011 08:40 AM
V8.2.4. Thanks!
12-19-2011 08:49 AM
Frist of all I will make sure there are no packet drops at transport layer. Extended ping can help in that.
Second I will remove - I remember it has got few bugs in older version.
security-association lifetime kilobytes 4608000
If you suspect this is causing because of rekey-
This command will help you to find- sh vpn-sessiondb detail l2l
output should look like
Rekey Int (T): 28800 Seconds Rekey Left(T): 20000 Seconds
Rekey Int (D): 413696 K-Bytes Rekey Left(D): 1 K-Bytes
Thanks
Ajay
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide