- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Gre Tunnel traffic being dropped
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gre Tunnel traffic being dropped
Hi
We have 2 R81.10 appliances in 2 separate sites, connected over our WAN. Behind each firewall, there is a wireless controller. The 2 wireless controllers are configured to connect to each other via Gre tunnels. However, the gre tunnel is not getting established between these 2 controllers. Each controller also have other gre tunnels to other wireless controllers at other sites on the WAN, which are established and working. It appears it is only the gre traffic between the 2 main controllers that is getting dropped at each firewall.
If I run tcpdump, I can see the traffic coming in to the interface but not going out. If I run fw ctl zdebug drop I get the message
"dropped by fw_handle_old_conn_recovery Reason: Other protocol packet that belongs to an old connection"
I'm unable to find much information on this particular message. Has anyone any ideas what it could point to and how I troubleshoot this? Any reason why some gre traffic goes through and other traffic is dropped?
Many Thanks
Roy
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk121933 talks to a similar drop reason for UDP traffic flows.
Can I confirm your connect persistence settings, are they set to keep or rematch?
Is the issue always present or only after someone performs a policy installation for the intermediate gateway?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk121933 talks to a similar drop reason for UDP traffic flows.
Can I confirm your connect persistence settings, are they set to keep or rematch?
Is the issue always present or only after someone performs a policy installation for the intermediate gateway?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Chris
Thanks for that. I initially went through the sk article but did not see any difference. I decided to go through the clear connections steps on both gateways and that appears to have resolved the issue.
Thanks
Roy
