This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec VPN to Draytek do not reconnect randomly

Hi,

I have XGS-126 as IPSec VPN client, calling Draytek router as VPN server. I also tried to reverse sides, but the problem remains the same.

From time to time, very randomly, it might be once every 2-3 weeks, or even so frequently like 4 times in 1 hour, VPN tunnel drops and does not re-establish connection. Sometimes manually clicking the red VPN dot establishes connection, but sometimes not.

Sophos LOGS are not helping me to diagnose, just a lot of:

IKE message retransmission to <Draytek IP> timed out. Check if the remote gateway is reachable.

I have VPN Profile settings just mirrored, what's on Draytek side:

  • IKE Phase 1, Re-key connection = ON
  • DPD = ON
  • DPD check every: 60 seconds
  • DPD When Peer Unreachable = Re-initiate
  • Dos Protection = OFF
  • DoS & Spoof exceptions added for both IPs as source and destination

When there was Draytek - Draytek VPN, on the same lines, VPN was rock-stable, never ever had problems.

Ideas welcome.



This thread was automatically locked due to age.
Parents
  • Hi Andrej Pirman

    Make sure Phase I and Phase II are same on both Sophos and other side router as well as try with Remote ID and Local ID settings

    Thanks and Regards

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Hi  

    For now and with your excellent help, this looks most promissing. Since we did this change, VPN is up and running. I hope it will stay and will certainly report back in a day or two. For now I am monitoring connection. Thank you a lot!

    console> system ipsec-acceleration disable

  • Hi  , I am also with Sophos. I was just curious, what SFOS release do you have running on the XGS-126?

  • Hi,

    at the moment it is still SFOS 19.0.1 MR-1-Build365 firmware.

    So far we figured out, that VPN drop outs were caused by Draytek, which was VPN server for one Sophos device and another Draytek device. After VPN dropout, that other Draytek did call back and re-initiated VPN tunnel UP very soon, but Sophos somehow did not. 

    As a workaround we reversed the VPN tunnel direction, so that Draytek is calling Sophos, meaning after each dropout Draytek re-initiates connection to Sophos and connectivity is restored.

    But it means we only masked out the problem.

Reply
  • Hi,

    at the moment it is still SFOS 19.0.1 MR-1-Build365 firmware.

    So far we figured out, that VPN drop outs were caused by Draytek, which was VPN server for one Sophos device and another Draytek device. After VPN dropout, that other Draytek did call back and re-initiated VPN tunnel UP very soon, but Sophos somehow did not. 

    As a workaround we reversed the VPN tunnel direction, so that Draytek is calling Sophos, meaning after each dropout Draytek re-initiates connection to Sophos and connectivity is restored.

    But it means we only masked out the problem.

Children
No Data