Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today

Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today

Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago - last edited 2 weeks ago
Hardware Version: V1
Firmware Version: 5.15.8.12

I have 2 controllers with 2 sites each, I have Ipsec vpn connections between locations, since this morning they no longer connect either manually or automatically. I didn't make any changes in any of the controllers, they just disconnected and don't reconnect, I redid the settings, I tried on automatic, nothing just doesn't connect, and the worst thing is that absolutely nothing appears in the logs!. I don't know what else to do, I restarted the controller, I restarted routers, but nothing. I mention that I have 3 Er605 routers and a router ER706W. A controller is OC200 and a controller is software on an on-premise server, I mention that there are 4 locations in total, 3 locations have ER605 routers, and one location has ER706W. 

Omada Hardware Controller OC200 1.0: FW: 1.31.3 Router : ER706W v1.0 : FW : 1.1.2 Switch : TL-SG2008 V4_4.20.0 and TL-SG108E V5_20191021 AP: EAP610 V3_1.4.3 and TL-WA801N V6_200116
  0      
  0      
#1
Options
28 Reply
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago

  @Sadiqus 

 

check if you are using a hyphen in the VPN name, change it to an underscore , hyphens are no longer supported

 

  0  
  0  
#2
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago - last edited 2 weeks ago

  @MR.S 

No, i don't

 

 

Omada Hardware Controller OC200 1.0: FW: 1.31.3 Router : ER706W v1.0 : FW : 1.1.2 Switch : TL-SG2008 V4_4.20.0 and TL-SG108E V5_20191021 AP: EAP610 V3_1.4.3 and TL-WA801N V6_200116
  0  
  0  
#3
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago

  @Sadiqus 

 

then i don't know, i see you have auto vpn, i've never gotten that to work. do you have problems with all vpn tunnels?
do you have a fixed ip on wan or is it dynamic? have you checked that you have the same ip as before on wan?

 

  0  
  0  
#4
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago - last edited 2 weeks ago

  @MR.S 

It also worked on auto, but now it doesn't want to work on auto anymore, But I had no control over the VLANs, except with many setbacks in the ACL. 

 

All my 4 IPS are fixed, and no, just this site-to-site, i have wireguard also, It works perfectly! 

Omada Hardware Controller OC200 1.0: FW: 1.31.3 Router : ER706W v1.0 : FW : 1.1.2 Switch : TL-SG2008 V4_4.20.0 and TL-SG108E V5_20191021 AP: EAP610 V3_1.4.3 and TL-WA801N V6_200116
  0  
  0  
#5
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago

  @Sadiqus 

 

I have a few ipsec tunnels but it just works very strangely, you didn't answer whether you have a fixed IP or dynamic IP on the WAN.

 

  0  
  0  
#6
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago - last edited 2 weeks ago

I replied in the previous post! I avoid double posting! 

Omada Hardware Controller OC200 1.0: FW: 1.31.3 Router : ER706W v1.0 : FW : 1.1.2 Switch : TL-SG2008 V4_4.20.0 and TL-SG108E V5_20191021 AP: EAP610 V3_1.4.3 and TL-WA801N V6_200116
  0  
  0  
#7
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago

  @Sadiqus 

 

ok, try deleting the tunnel on both sides and re-creating it if you haven't tried that.

 

  0  
  0  
#8
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago - last edited 2 weeks ago

  @MR.S 

 

I tried the following: deleted and redid the links,  I have redone all settings from 0, restarted routers, restarted the controller, nothing worked, I even tried to change who is the initiator and who is the responder, he just doesn't want to connect, and the strangest thing seems to me the fact that in the logs he doesn't tell me anything! There was absolutely no reference to the vpn, other times, it would send me a notification that the tunnel was disconnected or could not be connectedI. Now there is absolutely nothing, nowhere! And another oddity, he doesn't want to connect to the automatic anymore! 

Omada Hardware Controller OC200 1.0: FW: 1.31.3 Router : ER706W v1.0 : FW : 1.1.2 Switch : TL-SG2008 V4_4.20.0 and TL-SG108E V5_20191021 AP: EAP610 V3_1.4.3 and TL-WA801N V6_200116
  0  
  0  
#9
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago

  @Sadiqus 

 

yes it seems strange, I did a test here now with a manual ipsec tunnel between an ER605v2 and an ER706W it connected without any problems. ER706W also has an ipsec vpn to a Cisco firewall so the router is not a problem. it is a bit difficult to give any advice since I know very little about your solution, there could be 100 things that could cause problems, I suggest you contact tp-link support they can remotely control to get a look at the whole thing

 

 

  0  
  0  
#10
Options
Re:Ipsec VPN site-to-site it doesn't work anymore, it doesn't connect anymore from today
2 weeks ago

  @MR.S 

Where can I contact them? 

Omada Hardware Controller OC200 1.0: FW: 1.31.3 Router : ER706W v1.0 : FW : 1.1.2 Switch : TL-SG2008 V4_4.20.0 and TL-SG108E V5_20191021 AP: EAP610 V3_1.4.3 and TL-WA801N V6_200116
  0  
  0  
#11
Options