Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Remove Stale Peer from IPsec l2l connection

Status
Not open for further replies.

nhidalgo

MIS
Jun 13, 2001
619
0
0
US
I have a router with two internet connections. One is DSL one is a ceullar hwic. I have them setup with a flouting static route, make the dsl the primary connection. The vpn establishes fine via the dsl, i then pull the plug on the dsl connection and the Hwic fires up. The problem is the tunnel doesn't come up for 51 minutes. I keep getting phase 2 errors until the asa finally removes the old peer address for the tunnel. Is there a setting to adjust when stale address are removed.

ASA 5510 ver 7.
Cisco 2801 12.4

Thanks
 
don't see one

show crypto isakmp sa

Active SA: 58
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 58

1 IKE Peer: 71.242.241.***
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
2 IKE Peer: 71.245.62.***
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
3 IKE Peer: 141.158.133.***
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
4 IKE Peer: 71.242.238.***
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
 
try setting up your Dead Peer detection. i think its dpd ?
 
looks like dead peer detection is only for ssl vpn, i am still looking at it though
 
try:

clear ipsec sa peer <ip.addr>

this will clear the connection.

to clear all connections:

clear ipsec sa

-Ryan
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top