VPN UDP500 doesnt hit our firewall for some customers

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VPN UDP500 doesnt hit our firewall for some customers

L0 Member

Hi. I have a strange issue..

It all began when our "LAG/LACP" in our firewall reported error but then came alive again.

After that 20-30% of our ipsec vpn customers cant connect to us over UDP 500.

Sporadicaly it can change - customer1 who couldnt connect yesterday might be able to connect tomorrow and vice versa.

It (UDP500) seems to disappear on the way to our firewall - is that possible?

1. Customer firewalls are trying to setup vpn to our company but we cannot see that UDP 500 hits our firewall. If we change the ip in our end and at the customer end (ike tunnel) the tunnel comes up.

2. Other customer firewalls (same brand) can setup vpn to us to the exact same firewall at our end to the old "ip".

What have we tried?

- Rebooted all equipment including isp router

- Upgraded vpn in both ends (shouldnt be the issue)

- Captured packets in/out cant see nothing more than that UDP500 doesnt get to us from some customers, but as saied above - if we change ip - it does

- Disabled one LAG/LACP interface at the time

- A lot more to it..

Ideas?

- Disable LACP on the LAG/Etherchannel to "passive"? Wouldnt be recommended?

Equipment: PaloAlto, Cisco, Juniper, IBM

2 REPLIES 2

L7 Applicator

I'm not sure from you description but I think your topology is this.

Customer---Internet---Cisco-----PA v-wire---Juniper terminating VPN

You mention packet captures not seeing traffic at the Juniper vpn endpoint.

Can you run a packet capture on the PA to see if the traffic is visible there.

How to Run a Packet Capture

Also check the traffic logs and threat logs for the ip addresses on the tunnel communication to see what is logging.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Customer - Internet - ISP Cisco - PA - Cisco Core - Juniper and Cisco VPNs

We cannot see UDP 500 in our PA or in our Datacenters Cisco sw/router close to our PA.

Will update with more info along the day.

Thanks Steven!!

  • 2282 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!