Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > PIX dynamic VPN question

Reply
Thread Tools

PIX dynamic VPN question

 
 
Rob
Guest
Posts: n/a
 
      06-19-2006
Hi,
I am having problem with our branch office. . They have PIX 501 and here we
have PIX515. Last time when they lost VPN connection to our end, I told them
to reboot 501 (remote PIX) but VPN didnt come back. They do dynamic VPN to
515 end. To me rebooting 501 should bring the VPN back on, since they
initial VPN connection. I aksed a user to ping one of our machine here using
private IP from her computer because I thought that should help but didnt,
So finaly we had to telnet to 501 and do a ping inside in order to bring the
VPN on.
Is this normal? is there anyway to fix this issue?
Thanks for any help-Rob


 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      06-19-2006
In article <4496b76b$(E-Mail Removed)>, Rob <(E-Mail Removed)> wrote:

>I am having problem with our branch office. . They have PIX 501 and here we
>have PIX515. Last time when they lost VPN connection to our end, I told them
>to reboot 501 (remote PIX) but VPN didnt come back. They do dynamic VPN to
>515 end. To me rebooting 501 should bring the VPN back on, since they
>initial VPN connection. I aksed a user to ping one of our machine here using
>private IP from her computer because I thought that should help but didnt,


That -should- have worked.

>So finaly we had to telnet to 501 and do a ping inside in order to bring the
>VPN on.


>Is this normal? is there anyway to fix this issue?


Are you configured for isakmp identity address or for
isakmp identity hostname ? If you are configured for address then
it can take 20-30 minutes to be able to resume a connection after
the IP address changes.
 
Reply With Quote
 
 
 
 
Rob
Guest
Posts: n/a
 
      06-19-2006

"Walter Roberson" <(E-Mail Removed)> wrote in message
news:0GAlg.66435$IK3.51717@pd7tw1no...
> In article <4496b76b$(E-Mail Removed)>, Rob <(E-Mail Removed)> wrote:
>
> >I am having problem with our branch office. . They have PIX 501 and here

we
> >have PIX515. Last time when they lost VPN connection to our end, I told

them
> >to reboot 501 (remote PIX) but VPN didnt come back. They do dynamic VPN

to
> >515 end. To me rebooting 501 should bring the VPN back on, since they
> >initial VPN connection. I aksed a user to ping one of our machine here

using
> >private IP from her computer because I thought that should help but

didnt,
>
> That -should- have worked.
>
> >So finaly we had to telnet to 501 and do a ping inside in order to bring

the
> >VPN on.

>
> >Is this normal? is there anyway to fix this issue?

>
> Are you configured for isakmp identity address or for
> isakmp identity hostname ? If you are configured for address then
> it can take 20-30 minutes to be able to resume a connection after
> the IP address changes.


It is configured for IP:
On remote 501 I have:

isakmp enable outside
isakmp key ********* address 515-IP netmask 255.255.255.255
isakmp identity address
isakmp policy 10 authentication pre-share

On 515:
isakmp key ******** address 0.0.0.0 netmask 0.0.0.0 no-xauth no-config-mode
isakmp identity address
isakmp policy 10 authentication pre-share

The IP has not be changed, just we had a power failure on remote site (501)
and then even we rebotted PIX a couple of times or ping from a worksatation
didnt bring the VPN back up (Internet was up).
Any idea?
Thanks-Rob





 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
VPN PIX-_static PIX ; PIX-dynamic_PIX ; VPN Client Svenn Cisco 3 03-13-2006 09:25 AM
PIX-to-PIX vpn + remote Access VPN not working Marko Uusitalo Cisco 1 04-11-2005 12:45 PM
mixing pix-to-pix vpn and pptp-dial-in-vpn on pix501 Tom Cisco 4 11-17-2004 02:18 PM
PIX to PIX VPN and VPN Client to PIX Config Example? GVB Cisco 1 02-06-2004 07:44 PM
Building VPN's: Static/Dynamic//IOS/PIX/Cisco VPN Client/ all at the same time hk Cisco 0 11-25-2003 02:47 AM



Advertisments