vpn with cisco router is unstable.sudden spikes and packet losses. anyone knows how to configure dpd timers? I know we can set those through a management server. but its a locally managed gw.Corexl and securexl are enabled. Smartaccel that helps to increase the throughput of the gateway has also been enabled.CPU and memory on the gateway is also fine, nothing to big to be worried about.CPU is under 15% and the gw is using about 4gb/8gb of memory.
The customer has a application that has a timeout session of 5 seconds and when the tunnels are up everything works but when the gw deletes the negotiation it takes time to build again and thatss why the customer has been complaining about it.Funny thing is that on the same device, theres another VPN with a cisco router and its working completely fine.
getting this from the vpn debug on the 1800 appliance:
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] Sent Notification to Peer 6797e796: DPD ACK
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] Notification to Peer 6797e796: Sent Notification: DPD ACK
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] < FWIKE_PACKET_END > Id = 181279
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] < FWIKE_EXCH_END > Id = 181279
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] < FWIKE_ROLE_END > Id = 181279
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] TalkToEngine: Engine RC is << FWIKE_SND_NOTIFY >>
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] TalkToEngine: sending notification once
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] NegotiationTable::NegotiationUpdated: Updating indices for: 0xeb6ba90
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] NegotiationTable::DeleteNegotiation: Invoked for:
[sfwd 22516 4152900864]@GW[11 Sep 19:06:24] neg ptr: eb6ba90 ass: ec5a3b0 wait4: 00
msgId: ad0b372c method: 00 00 cookie: ad30775dc886b64e
req type: 13 SPIs: 00
[sfwd 22516 4152900864]@Ttpl-GW[11 Sep 19:06:24] NegotiationTable::DeleteNegotiation: peer: x.x.x.x local_ifn: -1 peer_ip: 0.0.0.0 found in negByTunnel hash