<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN woes in Archive</title>
    <link>https://business.forums.bt.com/t5/Archive/VPN-woes/m-p/41217#M6290</link>
    <description>&lt;P&gt;Me too, knobbster, me too ...&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jun 2012 14:12:43 GMT</pubDate>
    <dc:creator>dcdewick</dc:creator>
    <dc:date>2012-06-20T14:12:43Z</dc:date>
    <item>
      <title>VPN woes</title>
      <link>https://business.forums.bt.com/t5/Archive/VPN-woes/m-p/41151#M6288</link>
      <description>&lt;P&gt;I used to have a VPN connecting my two sites that worked faultlessly using Demon Internet and a different telecomms supplier. The VPN is established as an IPSEC VPN between two Watchguard firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Following a policy change (not mine!) at our remote site I recently had installed three new BT ADSL lines with BTHub3 modems, bonded together to provide a single internet connection through a BT recomended third party suplier, Sharedband. I reconfigured the VPN on the firewalls to reflect the new IP address at the remote end, and updated the WAN interface MTU size as instructed by the company providing the bonding service. I now have my VPN dropping at least once every hour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VPN drops when the DPD protocol used to "heartbeat" the VPN connection times out. I tried using IKE keepalive packets instead - same result. I tried switching off 2 of the three routers used for bonding, to re-create a single ADSL connection, same result. The VPN drops consistently thoughout the day and night, so it appears that the reasons for the drop are not traffic related. Latency between the firewalls is fairly consistent at about 58ms on average, although some hops show as high as 380ms:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp; &lt;FONT face="andale mono,times"&gt;Date/Time: 19/06/2012 10:45:23 to 19/06/2012 11:35:15&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;Hop Sent Err&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; PL%&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Min&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Max&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; Avg&amp;nbsp; &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;2&amp;nbsp;&amp;nbsp; 300&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;3&amp;nbsp;&amp;nbsp; 300&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; 179&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;4&amp;nbsp;&amp;nbsp; 300&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; 222&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; 19&amp;nbsp; &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;5&amp;nbsp;&amp;nbsp; 300&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0&amp;nbsp;&amp;nbsp; &amp;nbsp; 15&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; 371&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; 19 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;6&amp;nbsp;&amp;nbsp; 300&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0&amp;nbsp;&amp;nbsp; &amp;nbsp; 15&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 58&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; 19 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&amp;nbsp;7&amp;nbsp;&amp;nbsp; 300&amp;nbsp; 12&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.0&amp;nbsp;&amp;nbsp; &amp;nbsp; 54&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; 76&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; 57&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The issue is not with the firewalls, as they previously worked without a problem. Hours spent diagnosing logs with my firewall support show that the VPN drop is the result of a connection loss.The issue does not appear to be with the ADSL bonding as the problem exists with only a single line operational. BT tell me the circuits are all ok. The bonding service provider has configured his routers to provide access to the external interface of my remote firwall (host allocation). Pingplotter shows a consistent 4% packet drop on the last hop to my remote firewall, and error rate 12 times higher than on any other hop between the sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What else to try ? &lt;img id="smileyfrustrated" class="emoticon emoticon-smileyfrustrated" src="https://business.forums.bt.com/i/smilies/16x16_smiley-frustrated.gif" alt="Smiley Frustrated" title="Smiley Frustrated" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2012 10:46:00 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/VPN-woes/m-p/41151#M6288</guid>
      <dc:creator>dcdewick</dc:creator>
      <dc:date>2012-06-19T10:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN woes</title>
      <link>https://business.forums.bt.com/t5/Archive/VPN-woes/m-p/41165#M6289</link>
      <description>&lt;P&gt;Good luck on this. I got nothing on top of my head here. But I would love to have some shre their thoughts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2012 18:28:46 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/VPN-woes/m-p/41165#M6289</guid>
      <dc:creator>knobbster</dc:creator>
      <dc:date>2012-06-19T18:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN woes</title>
      <link>https://business.forums.bt.com/t5/Archive/VPN-woes/m-p/41217#M6290</link>
      <description>&lt;P&gt;Me too, knobbster, me too ...&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2012 14:12:43 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Archive/VPN-woes/m-p/41217#M6290</guid>
      <dc:creator>dcdewick</dc:creator>
      <dc:date>2012-06-20T14:12:43Z</dc:date>
    </item>
  </channel>
</rss>

