Some ipsec questions

I'm having some trouble trying to make a vpn ipsec between my debian firewall and a cisco asa.

The confs are like this:
my net                  my firewall        cisco asa          remote net

When the tunnel is down, if i try to ping from to 10.13.10.x/24 the tunnel is not going up automatically, but instead i have to do a racoonctl cpn-connect
Is that normal or i made something wrong?


