VPN Connection - Frustrating Morning!

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

VPN Connection - Frustrating Morning!

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
VPN Connection - Frustrating Morning!
VPN Connection - Frustrating Morning!
2021-04-22 13:13:39 - last edited 2021-11-04 13:39:52
Model: TL-R600VPN  
Hardware Version: V4
Firmware Version: 4.0.4 Build 20200313 Rel.41831

 

I have three locations all using the R600VPN for firewall. All VPN Site-To-Site connections were up this morning. This is what I have:

 

Site A

Site B

Site C

 

Site A has a VPN to Sites B and C

Site B has a VPN to Sites A and C

Site C has a VPN to Sites A and B

 

  I am at site A working through the VPN to site C. I notice the VPN drops. Usually not a big deal as if it happened in the past, the connection restored in seconds without further issue. But this one is not restoring. I look at site A R600 log and see that the connection is just restored and go to VPN/IPSec, IPSec SA page and it reports the SPI. But still no connection to any client at Site C. So, I go back to the logs and notice the Site A <-> C connection keeps dropping and reconnecting. I first assumed Site C has an internet connection problem.

 

  From site A, I can log into Site B without problems. This tells me Site A does not have an internet problem. From Site B I can connect to clients at Site A, obviously, and the there is also no problem connecting from Site B to C!! Sites A and B have the same ISP. Site C has a different ISP. From Site B, I connect to a client at Site C and verify that Site C does not have a problem with the internet, but also confirm that I cannot access any clients from Site C to Site A. I also verify that I can connect back to Site B clients from Site C.

 

  I rebooted Site C R600 but no help. I cannot reboot Site A R600 at this time as I would hate to loose the Sites A <-> B VPN connection.

 

  Sometimes I would like to throw these devices out, but we have these because I pushed for them.

 

  What could be causing this?

 

More info: I have disabled/enabled the VPN connection from both Sites A and C. No help.

  0      
  0      
#1
Options
2 Reply
Re:VPN Connection - Frustrating Morning!
2021-04-23 08:46:51

Dear @urbnsr,

 

urbnsr wrote

I look at site A R600 log and see that the connection is just restored and go to VPN/IPSec, IPSec SA page and it reports the SPI. But still no connection to any client at Site C. So, I go back to the logs and notice the Site A <-> C connection keeps dropping and reconnecting.

 

Could you upload the log information of both routers deployed at Site A and Site B?

 

If possible, you could try to capture the packets from the WAN on both routers for further analysis.

Note: to capture the packets, you need to configure Port Mirror on the routers first.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#2
Options
Re:VPN Connection - Frustrating Morning!
2021-04-23 15:29:40

I'll have to consider those steps if it happens again.

 

  Equally frustrating was that after I sort of gave it a rest, I noticed two hours later that the connection had fully restored to the point that I could finish my work from Site A to Site C without any intervention from me.

 

The one thing I wonder about, though - Do these routers have some type of temporary learning feature? Just before the link went down, I had maybe three to four connections through the VPN from Site A to C. Is it possible that Site C's router determined that there were too many packets collectively coming from one IP address and went into a "safe" mode? And possibly after a couple of hours (even through a reboot), a cache or session ID expires to allow the VPN connection to fully restore?

 

  Just some thoughts.

  0  
  0  
#3
Options