Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moudar
Advisor

VPN logs

Hi

When logs from a specific VPN community look like this:

kort.JPG

All logs are "key install" what i know is that key installation happens as configured on the advanced settings of the community:

Phase 1: 240 mins

Phase2: 3600 seconds

So why it is happening all the time?

What does that mean, a customer is complaining that they are loosing connection !

How to troubleshoot this problem?

0 Kudos
20 Replies
AmirArama
Employee
Employee

Start with reading the data inside those logs, see if they are good events, or errors / failures.

0 Kudos
the_rock
Legend
Legend

Hey bro,

Can we please see the whole log? Just blur out any sensitive data.

Andy

0 Kudos
Moudar
Advisor

 

All logs are same:

kort.JPG

the_rock
Legend
Legend

Thank you! So quick mode would be phase 2 issue...can they verify all the settings do indeed match?

Andy

0 Kudos
Moudar
Advisor

So in normal cases, how often should we see "key install" log other than the 240 and 3600 defaults?

0 Kudos
the_rock
Legend
Legend

I know defaults are 1 day for phase 1 and 1 hour for phase 2.

Andy

0 Kudos
Moudar
Advisor

Under normal circumstances, how often should we see "key install" logs apart from the 240 and 3600 defaults? I mean, how frequently do these logs typically appear?

The tunnel is up so phase 2 is OK i think!

kort.JPG

0 Kudos
Lesley
Mentor Mentor
Mentor

Is there an outage during or before/ after the key install time stamp? From my point of view it looks like you are receiving key install. This could be an indication that the issue should be check on the other side of the tunnel. To proof this theory a vpn debug in ikeview would help 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Moudar
Advisor

Yes, customer is experience an outage.

I am trying to download the Ikeview but website is down!?

kort.JPG

any other link to get Ikeview?

0 Kudos
the_rock
Legend
Legend

I just tried, worked for me.

Andy

0 Kudos
Moudar
Advisor

it works now!

On my gateway i have iked0.elg, iked1.elg and iked2.elg

there is no ike.elg and ikev2.xmll  !

kort.JPG

which one should be used in ikeview?

0 Kudos
the_rock
Legend
Legend

Either of those should work.

0 Kudos
Lesley
Mentor Mentor
Mentor

Have you enabled vpn debug truncon for debug start? Reproduce issue and turn off vpn debug truncoff

files rotate on their own no need to delete them. Copy them and load them in ikeview.

if you see remote peer ip in ikeview you are on the right track

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Moudar
Advisor

the command: vpn debug truncon, can it focus on specific community or it only debugs all S2S VPN?

0 Kudos
the_rock
Legend
Legend

I dont believe it can be done for specific community.

0 Kudos
Moudar
Advisor

I can now see this kind of log:

kort.JPG

and it is coming very often with different SPI

0 Kudos
the_rock
Legend
Legend

I would definitely examine phase 2 settings, because thats what those messages relate to.

Andy

0 Kudos
Lesley
Mentor Mentor
Mentor

Try under vpn comm to change to per gateway or per subnet change between them to see if there is improvement 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Moudar
Advisor

I have now changed it to "per Gateway" and my gateway started to "key install" on the other side gateway, i will keep an eye on it and back tomorrow with some insights. We have many subnets behind every gateway so maybe this is a better choice.

0 Kudos
the_rock
Legend
Legend

Hey bro,

I always found that option useful for route based tunnels. Not sure if thats type of tunnel you have, but if it is, it will help, 100%.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events