Lizano wrote: » So, I have this ASA, every day the site calls and says they are down. When they are down, they can ping public IP address but they cant ping by name, nor can they browse to websites. They also can't browse to IP addresses. The part that is killing me is that most of the time, they reboot it, sometime twice, and they are now able to surf. The ASA also has VPN connection that does go down when this occur. ICMP has been enable on the outside interface, and while the site reports they are down, I can ping the outsite interface. Any ideas?
FW#show conn
Lizano wrote: » The hardware has been replaced and this continues to happen, I got the device logging to a syslog server but nothing in the logs sheds any light.
cisco_trooper wrote: » Check the logs on the edge devices for link flaps, and check the firewall logs for lots of SYN timeouts, etc. Make sure that end user traffic is making it to the firewall when the outage is reported.
Lizano wrote: » Crypto lifetime mismatch was the fix.