Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN point-to-point

Status
Not open for further replies.

sunyasee

ISP
Apr 8, 2002
94
GB
Is there anyway of increasing the idle timeout on a VPN tunnel between two pix firewalls. The lifetime is set to 86400....

isakmp policy 10 lifetime 86400

But the VPN tunnel is only staying up for 20 minutes and then the tunnel drops. Any ideas?

Thanks ----

Sunyasee
 
HI.

The lifetime values (there are several different values) are not idle timeouts. When they expire it means that new "sa" keys should be exchaned.
There are different timeouts values for isakmp (phase 1) and for ipsec (phase 2).

Does the tunnel drop after 20 minutes of idle, or even when you transfer data it still drops?

Try to use a script or utility (like KIT from my web-site) that will ping every few minutes across the VPN tunnel.
Does it drop now?

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top