Tuesday, January 14, 2020

Huge mind F*CK network drops in s2s tunnel

Hi Guys, I need to borrow your brains for this, every hour on the 24th minute the connection times out, no matter when i start the connection or bound the vpn it always drops at 24, for example i start the connection at 9:00am the connection will timeout at 9:24 am, same behaviour as if i start at 9:22

so here's the description of the environment
I have tunnel between site A(sonicwall firmware 6.5.1.5) and site B(Cisco Asa firmware 9.13), there are no keepalives running, i have an app that makes connections every second to a port that runs on 12400 on the other side, the tunnel proposal are as follows
Phase 1

Main mode IKEv1

DH group 5

Encryption AES-256

Auth SHA256

Lifetime 28800

Phase 2

Protocol ESP

Encryption AES-256

Auth SHA256

Lifetime 3600

The troubleshooting steps i've tried
Changing the proposals to IKEv2

Enabled keepalive on both sides and on one side only

Switched from windows to linux to see maybe it's an OS thing

nping a different port (3389) while the app is running

One thing that did work is from cisco asa to azure and have it the app run there

Any ideas? as i'm losing both sleep and my mind on this



No comments:

Post a Comment