cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2370
Views
0
Helpful
2
Replies

VPN site to site ASA 5505 timeout

robin.esparre
Level 1
Level 1

Hi,

I have make a VPN between 2 firewall ASA 5505.
My vpn is working but after xxx minutes, the VPN disconnect automaticly.

How can i change it for have a "continuous VPN"?

thanks.

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

Enable ISAKMP keepalives on both ASA.

Hi Robin,

Your VPN's disconnect automatically because they don't hear anything from each other. It's like they are not talking to each other so each ASA believes the other is dead. In order to fix this you use DPD(dead peer detection).

What DPD does is to send keepalives to each other the default on ASA is 10 seconds by default. You can change that if you want but its not recommended. So, in this way both the devices know each other and keep the tunnel up and dont tear it down.

You enable DPD by typing the command under the tunnel group.

tunnel-group tunnel-group-name ipsec-attributes
isakmp keepalive enable


HTH
Kishore