Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > cisco vpn client session does not time out

Reply
Thread Tools

cisco vpn client session does not time out

 
 
chery
Guest
Posts: n/a
 
      08-24-2006
Hi,

Users were not able to get connected to my PIX 515E 6.3 using VPN
client. Upon further investigation I found that users could initially
connect to the PIX. But if they move out of the wireless range (i.e.
lose their network connectivity) while they are connected to the PIX,
then they will not be able to get connected back to pix.

I changed the idle-time for the vpn profile from 3 hours and reduced it
to 3 minutes. Still the session time out does not work and I could see
multiple entires for the user while giving
"sh isakmp sa".

I searched the group for similar problems but could not find any.
Have anyone of you faced a similar problem. Does any solution come
into your mind ?

Thanks,
Chery

 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      08-24-2006
In article < .com>,
chery <> wrote:

>Users were not able to get connected to my PIX 515E 6.3 using VPN
>client. Upon further investigation I found that users could initially
>connect to the PIX. But if they move out of the wireless range (i.e.
>lose their network connectivity) while they are connected to the PIX,
>then they will not be able to get connected back to pix.


Are you set for isakmp identity hostname or
isakmp identity address

The identity is used when a new phase 1 tunnel has to be
negotiated due to disconnection. The client sends its identity
as part of an ISAKMP clause that means "remove all previous
security associations from this identity". If the identity offered
upon reconnect does not happen to match the identity that was
previously offered, then the previous SA are not going to be
thrown away, and it is going to take time before the PIX figures
out that it should no longer bother to match against those particular
ACL entries associated with the SAs.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
USB Keys and Cisco VPN Concentrator / Cisco VPN Client ? TechGuy Cisco 3 02-05-2009 01:05 PM
Cisco VPN client OK - Checkpoint VPN client not OK Ned Cisco 0 10-12-2007 01:02 PM
Cisco VPN Client vs MS VPN Client jarcar Cisco 0 02-12-2004 12:22 PM
Help with Cisco VPN client 4.0.1 (and 4.0.3) - The VPN client could not find the adapters GUID MP Cisco 2 12-30-2003 03:55 PM
Building VPN's: Static/Dynamic//IOS/PIX/Cisco VPN Client/ all at the same time hk Cisco 0 11-25-2003 02:47 AM



Advertisments