T The Triage ManualTechnical Guides for IT Emergencies
P2 · Remote Access & VPN

Cisco ASA Site-to-Site IPSec VPN Drops Traffic When SA kB Lifetime Reaches Zero (Bug CSCtq57752)

A site-to-site IPSec VPN on a Cisco ASA running 8.6.1 shows the tunnel as up but stops passing traffic for an affected subnet under heavy load. The outbound Security Association's remaining key lifetime in kilobytes hits zero and fails to rekey due to Cisco bug CSCtq57752. Resolution is to upgrade to ASA 8.6.1(5) or later, or apply a workaround forcing time-based rekey before the data volume threshold is reached.

Indicators

Likely causes

Diagnostic steps

  1. Run 'show crypto ipsec sa' on the ASA and inspect 'sa timing: remaining key lifetime (kB/sec)' for both inbound and outbound SAs on the affected peer
  2. Identify whether the outbound SA shows 0 kB remaining while the seconds value is still non-zero — the signature of this bug
  3. Check ASA software version with 'show version' and compare against bug CSCtq57752 affected versions (notably 8.6.1)
  4. Temporarily restore connectivity by issuing 'clear crypto ipsec sa peer <peer-ip>' and confirm traffic resumes through the tunnel
  5. Monitor the SA over time to confirm the issue recurs as the kB lifetime depletes again, validating the rekey-failure pattern
  6. Review Cisco Bug Search Tool entry for CSCtq57752 to confirm fixed-in releases applicable to your platform

Resolution path

Prevention

Tools

References

Cisco ASAIPSecSite-to-Site VPNCSCtq57752rekeycrypto mapASA 8.6.1VPN troubleshootingSA lifetime