cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
0
Helpful
3
Replies

Packet Loss

Grayson Wells
Level 1
Level 1

I am not an expert on VPN tunnels so I am putting this out there to make sure I have covered all my bases. Every so often, sometime every 10 minutes sometimes every 30 minutes, we lose about 8 pings to a remote site that rides a site-to-site VPN tunnel. This tunnel is between two ASA5520's. The SA lifetime is 8 hrs and the traffic volume is at 4608000. My first thought was that it is hitting the traffic volume and causing the tunnels to rebuild. However, if you force the tunnels to rebuild you barely lose a ping or two. I have run out of ideas and the entity providing transport connectivity is annoyed at the idea that I think they caused the problem. Can anyone think of anything that would or could cause this? It started two weeks ago and no configuration had been changed at all. Thanks!

3 Replies 3

ajay chauhan
Level 7
Level 7

what ASA version you are running ?

V8.2.4. Thanks!

Frist of all I will make sure there are no packet drops at transport layer. Extended ping can help in that.

Second I will remove - I remember it has got few bugs in older version.

security-association lifetime kilobytes 4608000

If you suspect this is causing because of rekey-

This command will help you to find- sh vpn-sessiondb detail l2l

output should look like

  Rekey Int (T): 28800 Seconds          Rekey Left(T): 20000 Seconds

  Rekey Int (D): 413696 K-Bytes        Rekey Left(D): 1 K-Bytes

Thanks

Ajay