Community discussions

MikroTik App
 
jbabbtech
just joined
Topic Author
Posts: 20
Joined: Thu Sep 30, 2010 4:17 am

VPN to ASA 5505 dying and never reconnecting.

Sat Nov 20, 2010 5:44 pm

Hello all. I have a site-to-site between a 750 and an ASA 5505. Remote PCs are on domain and are in need of constant connection as they use folder redirection and the domain's DNS servers. ASA config is standard at works with 11 other remote sites. Mikrotik seems to be source of problem Currently, if vpn drops, it will not pick back up on its own. The odd thing is, it tries and believes it has recovered. The SAs are formed but the encryption and hash are displayed as none. This effectively means the VPN thinks its up but truly isn't. And, of course, it will not attempt renegotiation until its timers expire. I assume the Cisco breaks connection after 30 minutes of inactivity and then the problem above occurs when renegotiation is required. My current workaround is a ping ever five minutes from the DC to keep the tunnel up. I also have netwatch configured to flush SAs and ping the DC if the connection is ever dropped. This works but is not the right solution. If the the ASA is reloaded or loses power, I have to remote into the MK and: stop interesting traffic, flush SAs, (the weirdest part) change lifetime in policy, and restart interesting traffic. Any thoughts?
 
huntah
Member Candidate
Member Candidate
Posts: 287
Joined: Tue Sep 09, 2008 3:24 pm

Re: VPN to ASA 5505 dying and never reconnecting.

Tue Nov 23, 2010 8:59 am

HI this sound exactly like my problem.
Did you ever find a solution?
If there is no activity the tunnel dies..
But because this is IPTEL I have no means to ping the other side execpt for the MK router but the ping is not working because of the ping (cannot select interface)
 
jbabbtech
just joined
Topic Author
Posts: 20
Joined: Thu Sep 30, 2010 4:17 am

Re: VPN to ASA 5505 dying and never reconnecting.

Tue Nov 23, 2010 8:38 pm

I have not found a final solution but surely there is a script for pinging from a particular interface. You could run this script from netwatch.

Who is online

Users browsing this forum: Google [Bot] and 96 guests