This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC - cannot route - route already in use

We have a router that establishes a ipsec connection with the UTM. This router has a dynamic IP and as such is set to "Respond Only" for the gateway in the ipsec site to site config on the UTM. Connects just fine.

Now, if we turn this router off, the ipsec connection drops as expected. However, the UTM seems to just sit there with the route established ie it doesn't detect the link is down and delete the route.

DPD seems to kick in about 120s at which time the security association (and route) is then deleted by the UTM. The remote router can then connect and establish an ipsec connection to the UTM.

However, if the remote router tries to connect to the UTM before this route is deleted by DPD, the UTM complains about the route already being in place. Obviously because it is still there. As the remote router retries, the UTM then further complains about the maximum number of retries being reached and the remote router cannot connect.

Any ideas for a workaround? My immediate thoughts are that the DPD detection time needs to be brough down on the UTM side so that the routes can be deleted.



This thread was automatically locked due to age.
Parents Reply Children
  • Dear Louis,

    glad to hear that the solution inspired by Josef and me was a success and solve the problem.

    Best regards 

    Alex 

    -

  • Yes. Thank you. TBH, I tried the SSL VPN but couldn't get it to work site to site due to the way Sophos uses their apc file. I got close with IPSEC eg DPD down to 20 secs but this wasn't enough and I wasn't convinced it would be 100% reliable eg 3 second drop in connection.

    Getting the OPVN site to site running with the UTM isn't quite straight forward either but hey ho, got there in the end and it's working a treat.