Cisco ASA Site-to-Site VPN Dropped Connection

May 29, 2009

On random, rare, occasions one of our offices will drop off the face of the Earth. After troubleshooting with users in that office, you’ll find that there is always one symptom:

They can browse the web but cannot access any network resources in the company.

What will work 99% of the time is entering these two commands into your Cisco ASA firewall:


clear crypto isakmp sa
clear crypto ipsec sa

What these two lines of code will do is drop ALL site-to-site vpn connections and rebuild the tunnels.
It takes about a minute or so for everything to start working again but these two commands have saved me time and again.

No related posts.

About the Network Technician

He lives in sunny San Diego, CA with his beautiful wife. He started his technical career with Windows technologies but is making his transition to network administration & information security. Contact Rowell via email, Facebook or Twitter - @rowelld.

Leave a Comment

CommentLuv Enabled

Previous post:

Next post: