|
Just about everyone on this list is
more qualified to answer than I am, but since I haven't seen any other replies,
I'll take a stab at answering.
I don't know about the Pix
specifically, but many firewalls have a Phase 2 setting that forces key
expiration after a specified period of time. This is to make sure the tunnel is
not sitting idle for long periods, susceptible to being abused. The symptoms you
describe would be consistent with one end of the VPN tunnel having a different
key expiration timing than the other end of the tunnel. It could be that one end
of the tunnel is forcing expiration, then the two ends auto-negotiate a new
tunnel... which is why the tunnel is down for five or ten minutes, then comes
back.
Long story short, I'd try checking for
compatible "force key expiration" settings on both ends of the
tunnel.
Hope this helps!
Scott Pinzon,
CISSP
WatchGuard
Technologies
_______________________________________________ firewall-wizards mailing list firewall-wizards@listserv.icsalabs.com https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [fw-wiz] SSH brute force list, Vatsal Mehta |
|---|---|
| Next by Date: | Re: [fw-wiz] VPN question, Dave Piscitello |
| Previous by Thread: | [fw-wiz] VPN question, Henderson, Bernadette |
| Next by Thread: | Re: [fw-wiz] VPN question, Dave Piscitello |
| Indexes: | [Date] [Thread] [Top] [All Lists] |