Sat Nov 20, 2010 5:44 pm
Hello all. I have a site-to-site between a 750 and an ASA 5505. Remote PCs are on domain and are in need of constant connection as they use folder redirection and the domain's DNS servers. ASA config is standard at works with 11 other remote sites. Mikrotik seems to be source of problem Currently, if vpn drops, it will not pick back up on its own. The odd thing is, it tries and believes it has recovered. The SAs are formed but the encryption and hash are displayed as none. This effectively means the VPN thinks its up but truly isn't. And, of course, it will not attempt renegotiation until its timers expire. I assume the Cisco breaks connection after 30 minutes of inactivity and then the problem above occurs when renegotiation is required. My current workaround is a ping ever five minutes from the DC to keep the tunnel up. I also have netwatch configured to flush SAs and ping the DC if the connection is ever dropped. This works but is not the right solution. If the the ASA is reloaded or loses power, I have to remote into the MK and: stop interesting traffic, flush SAs, (the weirdest part) change lifetime in policy, and restart interesting traffic. Any thoughts?