- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-07-2012 02:20 PM
I have a problem with the PAN keeping a tunnel connected to Watchguard firewalls.
Phase1
Main Mode
IKE Crypto: MD5-3DES-GP1
Lifetime: 8 Hours
DPD 5-5
Phase2
IPSec Crypto: MD5-3DES-NoPFS
Lifetime 8 Hours
LifeSize 128 MB
Proxy: Local 10.0.0.0/8 Remote: 192.168.4.0/24
I have tried just about every type of Authentication and Encryption possible but still cant get a stable tunnel. They will work for a day or 2 and then fail. I have to delete and rebuild the tunnels on the Watchguards to bring the connection back up.
I have not tried to play with the lifetime or size settings yet. I also have not tried Agressive mode yet. Anyone out there been able to make a stable tunnel with a Watchguard Firewall?
12-07-2012 03:56 PM
If the PA firewall is the responder, take a look at your ikemgr.log file. You can use this command to navigate using standard linux 'less' navigation:
> less mp-log ikemgr.log
Find the time of the most recent failure and see what the reason for the failure is, the log should give you pretty good details.
If the PA firewall is the initiator, you'll need to look at the logs on the Watchguard. It sounds like you're establishing correctly, but a re-key is likely failing. The log is your best bet for seeing the issue.
Does it re-establish by itself? How about if you use the test command:
> test vpn ipsec-sa tunnel <tunnel-name>
You may also try enabling tunnel monitoring on the PA firewall in the IPSec config (Network > IPSec Tunnels > (tunnel name) > General tab > Advanced > Tunnel Monitor. Configure an address on the other side of the tunnel.
Good luck!
Greg
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!