ASA 5505 – Tunnel Keepalive?
pitviper CCNP:Collaboration, CCNP:R&S, CCNA:S, CCNA:V, CCNA, CCENTMember Posts: 1,376 ■■■■■■■□□□
Is there an easy way to keep an ipsec-L2L VPN tunnel up while there is no interesting traffic? I have an ASA 5505 setup for backup internet/LAN VPN access in event that the MPLS network is down (which has been a big issue in this location!) – IP SLA tracking is setup to change routes in the event of a failure and it works great. The only problem is that when the primary MPLS connection is up, the tunnel eventually dies because there is no traffic passing. For monitoring purposes I’d like to keep the tunnel up all of the time. I tried using the “isakmp keepalive” command under the tunnel group, but that doesn’t seem to work. An EEM script on the router to ping out through the interface connected to the ASA would work – but there has to be a better way to accomplish this! Thanks!
CCNP:Collaboration, CCNP:R&S, CCNA:S, CCNA:V, CCNA, CCENT