refresh PIX VPN config.. old SAs

Nov 23, 2005 2 Replies

I've made some modifications to some VPNs on a 515 pix 6.3(3) due to the change of the network addresses of the remote private subnets. Everything works fine except the VPNs drop every minute for a few seconds.



debug crytpo sa shows me that the SAs for the old remote subnets still exist and/or are still being generated. Does anyone know of a way of refreshing the config to remove any trace of the old remote networks?



Thanks in advance



Did you "clear ipsec sa" ?

no. and neither did I "clear crypto isakmp sa". but I have now and all the stale entries have disappeared. Thanks for you help!

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required