Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

PIX VPN problem when remote peer changes IP

I have some VPNs between a PIX with static IP and several routers with dynamic IP.

When one of the remote routers changes its IP the PIX keeps the VPN with the old one and it doesn't allow the VPN with the new IP until I manually kill the old one...

Keepalives are activated.

Any help ?

Thank you.

5 REPLIES
New Member

Re: PIX VPN problem when remote peer changes IP

If you're using PIX OS 7 or 8 you can utilize the DefaultL2LGroup. Otherwise you can configure the PIX as an EasyVPN server.

New Member

Re: PIX VPN problem when remote peer changes IP

I am using the DefaultL2LGroup, the VPN works OK... but when the remote peer changes its IP the PIX doesn't allow the new VPN (with the new peer IP) until I manually "kill" the VPN with the old IP.

Silver

Re: PIX VPN problem when remote peer changes IP

Try reducing the sa lifetime.

HTH

Saju

New Member

Re: PIX VPN problem when remote peer changes IP

I don't think that solves the problem, I still have to wait until the lifetime expires.

Shouldn't the PIX realice that the old peer is dead and allow the new VPN ?.

The remote router is a Linksys.

Silver

Re: PIX VPN problem when remote peer changes IP

Try reducing the sa lifetime.

HTH

Saju

111
Views
0
Helpful
5
Replies
CreatePlease to create content