This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC - cannot route - route already in use

We have a router that establishes a ipsec connection with the UTM. This router has a dynamic IP and as such is set to "Respond Only" for the gateway in the ipsec site to site config on the UTM. Connects just fine.

Now, if we turn this router off, the ipsec connection drops as expected. However, the UTM seems to just sit there with the route established ie it doesn't detect the link is down and delete the route.

DPD seems to kick in about 120s at which time the security association (and route) is then deleted by the UTM. The remote router can then connect and establish an ipsec connection to the UTM.

However, if the remote router tries to connect to the UTM before this route is deleted by DPD, the UTM complains about the route already being in place. Obviously because it is still there. As the remote router retries, the UTM then further complains about the maximum number of retries being reached and the remote router cannot connect.

Any ideas for a workaround? My immediate thoughts are that the DPD detection time needs to be brough down on the UTM side so that the routes can be deleted.



This thread was automatically locked due to age.
Parents
  • Hi Louis,

    but that’s what DPD is for. The UTM or any other Router can’t detect the vanished tunnel without DPD timeout.

    What might be interesting, does the dynamic router keep the IP Address if it tries to reconnect after power off?

    But at the end you should lower the timeout. I don’t know the exact use case but how many disconnects does this device have a day. Is there really a difference if this lasts 30 or 120 seconds?

    Best regards 

    Alex 

    -

Reply
  • Hi Louis,

    but that’s what DPD is for. The UTM or any other Router can’t detect the vanished tunnel without DPD timeout.

    What might be interesting, does the dynamic router keep the IP Address if it tries to reconnect after power off?

    But at the end you should lower the timeout. I don’t know the exact use case but how many disconnects does this device have a day. Is there really a difference if this lasts 30 or 120 seconds?

    Best regards 

    Alex 

    -

Children