Networking-Blog

My WordPress Blog

Cisco: Stop Site-to-Site VPN Drop

By default, site-to-site VPNs timeout after 30 minutes of idle time. This is a pain for me when I first try to access a site and have the first few packets of my Remote Desktop session or ping or whatever drop. (Yes – those 3 seconds of my life are EXTREMELY valuable). Here’s the secret, straight from Cisco:
PIX/ASA 7.x and later

Enter the vpn-idle-timeout command in group-policy configuration mode or in username configuration mode in order to configure the user timeout period:

hostname(config)#group-policy DfltGrpPolicy attributes
hostname(config-group-policy)#vpn-idle-timeout none

Configure a maximum amount of time for VPN connections with the vpn-session-timeout command in group-policy configuration mode or in username configuration mode:

hostname(config)#group-policy DfltGrpPolicy attributes
hostname(config-group-policy)#vpn-session-timeout none

Cisco IOS Router

Use the crypto ipsec security-association idle-time command in global configuration mode or crypto map configuration mode in order to configure the IPsec SA idle timer. By default IPsec SA idle timers are disabled.

crypto ipsec security-association idle-time 
seconds 

Time is in seconds, which the idle timer allows an inactive peer to maintain an SA. Valid values for the seconds argument range from 60 to 86400.

Cisco Ipsec Vpn Multiple Crypto Maps

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key commstest address 1.1.1.1
crypto isakmp key commstest address 2.2.2.2
!
!
crypto ipsec transform-set securegz esp-3des esp-md5-hmac comp-lzs
crypto ipsec transform-set secure esp-3des esp-md5-hmac
crypto ipsec transform-set minimalgz esp-null esp-md5-hmac comp-lzs
crypto ipsec transform-set minimal esp-null esp-md5-hmac
!
crypto map comms 1 ipsec-isakmp
set peer 1.1.1.1
set transform-set secure
match address 102
crypto map comms 2 ipsec-isakmp
set peer 2.2.2.2
set transform-set secure
match address 103
crypto map comms 3 ipsec-isakmp
set peer 1.1.1.1
set transform-set secure
match address 104
crypto map comms 4 ipsec-isakmp
set peer 1.1.1.1
set transform-set secure
match address 105
crypto map comms 5 ipsec-isakmp
set peer 1.1.1.1
set transform-set secure
match address 106
crypto map comms 6 ipsec-isakmp
set peer 1.1.1.1
set peer 2.2.2.2
set transform-set secure
match address 107
!
ip nat inside source list 101 interface FastEthernet0/0 overload
!
ip route 0.0.0.0 0.0.0.0 213.122.172.145
ip route 10.11.3.0 255.255.255.0 10.11.1.1
ip route 10.11.9.0 255.255.255.0 10.11.1.1
ip route 10.11.22.0 255.255.255.0 10.11.1.1
!
access-list 101 deny ip 10.11.1.0 0.0.0.255 10.11.0.0 0.0.255.255
access-list 101 deny ip 10.11.2.0 0.0.0.255 10.11.0.0 0.0.255.255
access-list 101 permit ip 10.11.1.0 0.0.0.255 any
access-list 101 permit ip 10.11.2.0 0.0.0.255 any
access-list 102 permit ip 10.11.1.0 0.0.0.255 10.11.20.0 0.0.0.255
access-list 102 permit ip 10.11.2.0 0.0.0.255 10.11.20.0 0.0.0.255
access-list 103 permit ip 10.11.1.0 0.0.0.255 10.11.0.0 0.0.255.255
access-list 103 deny ip 10.11.1.0 0.0.0.255 any
access-list 104 permit ip 10.11.2.0 0.0.0.255 10.11.0.0 0.0.255.255
access-list 104 deny ip 10.11.1.0 0.0.0.255 any
access-list 105 permit ip 10.11.22.0 0.0.0.255 10.11.0.0 0.0.255.255
access-list 105 deny ip 10.11.1.0 0.0.0.255 any
access-list 106 permit ip 10.11.3.0 0.0.0.255 10.11.0.0 0.0.255.255
access-list 106 deny ip 10.11.1.0 0.0.0.255 any
access-list 107 permit ip 10.11.9.0 0.0.0.255 10.11.0.0 0.0.255.255
access-list 107 deny ip 10.11.1.0 0.0.0.255 any
!
int fa0/0
crypto map comms