tonymullen
MIS
Hi, I'm wondering if someone can help...
I've got a pix 515 and a pix 501 that share the same subnet for their outside interfaces. I've set a vpn up between the two of them which worked great for a couple of weeks.
Now all of a sudden, the vpn seems to drop for a period of time so a ping -t to the other internal network range returns about 100 successes, and then around 100 fails (I'm not sure if these times are exact or not they are just estimates) before another 100 successes. This cycle just keeps on repeating.
When it fails then a sh crypto isakmp sa still shows that the tunnel is up but no traffic can flow. A sh crypto ipsec sa also shows that the tunnel is up (there are a couple of send errors but they don't seem to be going up - the current number is 3 and this has been going on for a couple of days).
I'm really confused. I've set the logging to notifications on the 501 (I'm reluctant to do this on the 515 due to the amount of traffic flowing through it) and I can't see any issues relating to the vpn.
Has anyone come accross anything like this and more importantly how do you fix it? Any pointers greatly apreciated
Tony
I've got a pix 515 and a pix 501 that share the same subnet for their outside interfaces. I've set a vpn up between the two of them which worked great for a couple of weeks.
Now all of a sudden, the vpn seems to drop for a period of time so a ping -t to the other internal network range returns about 100 successes, and then around 100 fails (I'm not sure if these times are exact or not they are just estimates) before another 100 successes. This cycle just keeps on repeating.
When it fails then a sh crypto isakmp sa still shows that the tunnel is up but no traffic can flow. A sh crypto ipsec sa also shows that the tunnel is up (there are a couple of send errors but they don't seem to be going up - the current number is 3 and this has been going on for a couple of days).
I'm really confused. I've set the logging to notifications on the 501 (I'm reluctant to do this on the 515 due to the amount of traffic flowing through it) and I can't see any issues relating to the vpn.
Has anyone come accross anything like this and more importantly how do you fix it? Any pointers greatly apreciated
Tony