 maxusa Premium join:2004-05-05 USA
2 edits | reply to Eric_T Re: VPN reconnect
Ping script is a good way to trigger the chk_conn timer. The input idle timer is supposed to help when no outbound traffic is expected (can not use chk_conn). Therefore, a combination of both timers on the router shall provide the desired result. Pair this with the other endpoint fine-tuning.
The real world evidence, however, suggests that IPsec interruptions (and loss of service) are inevitable. Our job is to minimize downtime to acceptable levels. |