Cisco Systems Keeping a site to site tunnel up indefinitely

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Keeping a site to site tunnel up indefinitely psychogenic 01-12-07
Posted by psychogenic on January 12, 2007, 3:48 pm
Please log in for more thread options
`Assuming links are good on both sides, is there a way to keep a site
to site vpn tunnel up at all times even when no actual traffic is being
sent across? aside from doing a ocntinuous ping. :(


Posted by Walter Roberson on January 12, 2007, 3:56 pm
Please log in for more thread options
>`Assuming links are good on both sides, is there a way to keep a site
>to site vpn tunnel up at all times even when no actual traffic is being
>sent across? aside from doing a ocntinuous ping. :(

It depends on the equipment (and software rev). Some allow you
to set keep-alives, others don't.


Posted by psychogenic on January 12, 2007, 3:59 pm
Please log in for more thread options

Walter Roberson wrote:
> >`Assuming links are good on both sides, is there a way to keep a site
> >to site vpn tunnel up at all times even when no actual traffic is being
> >sent across? aside from doing a ocntinuous ping. :(
>
> It depends on the equipment (and software rev). Some allow you
> to set keep-alives, others don't.

This is between a 2600 router and ASA 5510.


Posted by Walter Roberson on January 12, 2007, 4:02 pm
Please log in for more thread options

>Walter Roberson wrote:
>> >`Assuming links are good on both sides, is there a way to keep a site
>> >to site vpn tunnel up at all times even when no actual traffic is being
>> >sent across? aside from doing a ocntinuous ping. :(

>> It depends on the equipment (and software rev). Some allow you
>> to set keep-alives, others don't.

>This is between a 2600 router and ASA 5510.

The following might help:

http://www.cisco.com/univercd/cc/td/doc/product/software/ios123/123newft/123t/123t_7/gtdpmo.htm



Posted by on January 13, 2007, 11:41 pm
Please log in for more thread options

Walter Roberson wrote:
>
> >Walter Roberson wrote:
> >> >`Assuming links are good on both sides, is there a way to keep a site
> >> >to site vpn tunnel up at all times even when no actual traffic is being
> >> >sent across? aside from doing a ocntinuous ping. :(
>
> >> It depends on the equipment (and software rev). Some allow you
> >> to set keep-alives, others don't.
>
> >This is between a 2600 router and ASA 5510.
>
> The following might help:
>
>
http://www.cisco.com/univercd/cc/td/doc/product/software/ios123/123newft/123t/123t_7/gtdpmo.htm

That is interersting, thanks.

It's not clear what the OP is looking for. This does not keep the SA's
up.

There are seceral tools that might be used to persuate a
router to generate periodic traffic.

NTP

1. ##
ntp server some.address.across.vpn
don't point it at an actual server as ntp sends little traffic one it
is happy.

2.
Create GRE tunnel interfaces and point them
across the vpn, enable keepalives with the desired interval.

3. ## This one is the most official but I think needs certain feature
set.
Use SAA to send traffic, say pings, to real or non-existant hosts
across vpn.

4. ## wouldn't fancy this one much.
bgp peer would do too.

5.
I think certain feature sets have "cron". Schedule pings.


Similar ThreadsPosted
Keeping a site to site tunnel up indefinitely January 12, 2007, 3:48 pm
Site-to-site tunnel w/NAT, return packets decap but not routed? December 13, 2006, 7:52 pm
block ports out to internet but not out over site-to-site tunnel March 6, 2006, 6:33 pm
site to site IPSEC Tunnel question problem with NAT T November 2, 2006, 3:01 pm
both Easy VPN Server and a Site-to-Site tunnel on the same interface? January 21, 2008, 1:17 pm
PIX 8.x to ASA 8.x Site (static ip) to Site (dynamic ip) tunnel configuration February 20, 2008, 6:39 pm
site-to-site VPN tunnel with remote VPN clients June 21, 2006, 11:07 am
NetBIOS Name can not pass through the Site-to-Site VPN tunnel July 7, 2005, 11:24 pm
Using an SLA echo monitor via an ASA Site-to-Site Tunnel September 24, 2008, 3:27 pm
Re: Unreliable ADSL vs. site to site tunnel October 29, 2008, 11:21 am
DNS Issue over Site -Site VPN Tunnel. September 15, 2006, 1:57 pm
How can I know if the site-to-site VPN tunnel is working July 10, 2008, 11:16 am
Pix 501 - Site-to-Site VPN Tunnel January 31, 2006, 2:49 pm
Site to Site VPN Tunnel June 23, 2007, 11:14 am
Allow vpn client down a site to site tunnel from router A to router B July 29, 2008, 3:23 pm