Hi,

with this task I had the problem that although I have enabled isakmp-keepalives an all devices (ASA, R2 and R5), the switchover did not happen reasonably fast.

Interestingly, the switchover worked fine when switching from R2 to R5. Here I had a downtime of about 10 seconds. But when enabling the primary path over R2 again, the switchover did not happen even after minutes. The trick here was to clear the isakmp sa on the ASA. Then the renegotiation occurs and connectivity is there again. Switching back again to R5 works fine again. I don't know what to do here, because the ASA is the one in this scenario who should check that the tunnel-endpoint has moved and renegotate. Anyone ran into the same problem or knows how to proceed here?

Thanks,
airflow