AWS VPC Drops Cisco ASA VPN link

We have a VPN link into AWS, we have not really used it with any anger, but we are now trialing cool bit of replication technology.

This involves replicating the full server into the cloud see

Well everything works in terms of the software but my link kept dropping, well this is not strictly true, the link was up but not data would traverse the link !!!!!

After speaking to AWS support they pointed me, well they did not really point me in any direction :).

So to Google I went, there was nothing really about AWS and the ASA configuration or issues you may have, only how to debug how to get it working.

Nothing on why it suddenly stops. I then stumbled up on this post.

which then pointed me in the direction of the SA lifetime configuration. After then finding I concluded that there is a bug in the IOS and because of the amount of data traversing the link, the timeout was being reached and not renewing.

You therefore need to configure the timeout time to hit before the data transfer.

For me this was 10 minutes with the data set to 2147483647, I found setting this to 3 minutes just interrupted the whole transfer and therefore settle for 10.

So the line in my config were

crypto map amzn-vpn-map 1 set security-association lifetime seconds 600
crypto map amzn-vpn-map 1 set security-association lifetime kilobytes 2147483647
  1. Leave a comment

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

Open Source Made Easy

Unanswered Questions Answered

Helping you achieve more

The Survival Guides's Blog

How to Survive IT and Holidays is the best place for your personal blog or business site.

%d bloggers like this: