AZTCOFW / DOCUMENTATION
Troubleshooting IPsec VPNs
Configuration guides, troubleshooting and practical advice for AZTCOFW.
Articles
9 resultsConnection Hangs
IPsec does not gracefully handle fragmented packets. Many of these issues have been resolved over the years, but there may be some lingering problems. If hangs or packet loss are seen only when using specific protocols (
IPsec Log Interpretation
The IPsec logs available at Status > System Logs , on the IPsec tab contain a record of the tunnel connection process and some messages from ongoing tunnel maintenance activity. Some typical log entries are listed in thi
IPsec Logging
Examples presented in this chapter have logs edited for brevity but significant messages remain. Logging for IPsec may be configured to provide more useful information. To configure IPsec logging for diagnosing tunnel is
Some hosts work, but not all
If traffic between some hosts over the VPN functions properly, but some hosts do not, this is commonly one of four things: Missing, incorrect or ignored default gateway If the device does not have a default gateway, or h
Tunnel does not establish
First check the service status at Status > Services . If the IPsec service is stopped, double check that it is enabled at VPN > IPsec . Also, if using mobile clients, ensure that on the Mobile clients tab, the enable box
Tunnel establishes but no traffic passes
The top suspect if a tunnel comes up but won’t pass traffic is the IPsec firewall rules. If Site A cannot reach Site B, check the Site B firewall log and rules. Conversely, if Site B cannot contact Site A, check the Site
Tunnel Establishes When Initiating, but not When Responding
If a tunnel will establish sometimes, but not always, generally there is a mismatch on one side. The tunnel may still establish because if the settings presented by one side are more secure, the other may accept them, bu
Tunnels Establish and Work but Fail to Renegotiate
In some cases a tunnel will function properly but once the phase 1 or phase 2 lifetime expires the tunnel will fail to renegotiate properly. This can manifest itself in a few different ways, each with a different resolut
“Random” Tunnel Disconnects/DPD Failures on Low-End Routers
If IPsec tunnels are dropped on low-end hardware that is pushing the limits of its CPU, DPD on the tunnel may need disabled. Such failures tend to correlate with times of high bandwidth usage. This happens when the CPU o