Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend

Permanent tunnel question

Hey guys,

I had a question and I hope someone can give an answer. Just wondering, when someone sets up vpn site to site with say 1 central gateway and bunch of satellite gateways and its set as permanent tunnel, should tunnel management have 1 subnet per pair or gateway? Also, should tunnel_keepalive_method be set to tunneltest on all sides, or dpd on central gw and tunnel test on others?

Reason I ask is because we have customer who has intermittent vpn disconnect issues and sadly, TAC cant find any sk's or documents advising on how permanent tunnels between cp devices should be configured.

They have tunnel_keepalive_method set in guidbedit to dpd for central cluster and as tunneltest for all satellite ones and all satellite gw's are 1100 managed by another management server and all configured as externally managed gateways in dashboard for vpn purpose, so 1 central gateway in community and about 20 satellite ones, same vpn star community.

This all worked fine for so many months and all of a sudden yesterday, things started ocurring without any changes,

 

Any insight would be appreciated!

Thanks as always!

0 Kudos
4 Replies
Ruan_Kotze
Advisor

Long shot, but does this perhaps correlate with policy pushes?  I ran into the issue described in sk142355 a couple of times already.

0 Kudos
the_rock
Legend
Legend

Thank you for the reply, but not related. Customer has that enabled and VPN tunnels issue happens randomly, never after policy push.

0 Kudos
frankthetank_69
Explorer

Did you manage to get a answer to this?

I am also wondering how the permanent tunnels are supposed to work (check point to check point). I have seen that the satellite gateways encrypts the tunnel_test and on the central it gets decrypted. But when Central initiates a tunnel tests it does not encrypt it, in the other end at the satellite it gets dropped because it expects the packet to be encrypted. "Clear text packet should be encrypted" 

0 Kudos
the_rock
Legend
Legend

Actually yes. It turns out you set it as "one tunnel per gateway pair" and permanent tunnel in tunnel mgmt tab, which would present 0.0.0.0/0 as enc domain. This was back in R80.30 I believe, but ever since they went to R81 and above, never had the issue.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events