Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

No VPN Traffic Flows for 3 Minutes after Phase 2 ReKey

$
0
0

I have a couple of small business customers that are still using NS5GTs.  One of them has an Office in CA and another Office in Florida.  Both Offices have a static public IP and an NS5GT with a site-to-site policy-based VPN connecting them.  When the Phase 2 lifetime expires, both sides renegotiate the connection and it is back up in a second so all looks normal.  However, no traffic will pass over the VPN for almost exactly 3 minutes and then it resumes as normal.

Here are the event logs for one side:

2019-02-28 11:06:13 system info 00536 IKE<104.4.xxx.xxx> Phase 2 msg ID <112a9154>: Completed negotiations with SPI <c5ed3164>, tunnel ID <1>, and lifetime <86400> seconds/<0> KB.
2019-02-28 11:06:13 system info 00536 IKE<104.4.xxx.xxx> Phase 2 msg ID <112a9154>: Responded to the peer's first message.
2019-02-28 11:06:13 system info 00536 IKE<104.4.xxx.xxx> Phase 1: Completed Main mode negotiations with a <28800>-second lifetime.
2019-02-28 11:06:13 system info 00536 IKE<104.4.xxx.xxx> Phase 1: Responder starts MAIN mode negotiations.

The lifetime looks funny here because we changed it to one day to verify the problem occurs when the Phase 2 lifetime expires.

We also setup a ping test from a server on one side to a device on the other side and enabled logging on the policy to verify that traffic was actually being sent across the VPN:

2019-02-28 11:07:27 Encrypt 10.0.0.20:48782 10.0.1.8:14 59 sec 78 0 ICMP
2019-02-28 11:07:23 Encrypt 10.0.0.20:48781 10.0.1.8:14 60 sec 78 0 ICMP
2019-02-28 11:07:19 Encrypt 10.0.0.20:48780 10.0.1.8:14 61 sec 78 0 ICMP
2019-02-28 11:07:13 Encrypt 10.0.0.20:48779 10.0.1.8:14 59 sec 78 0 ICMP
2019-02-28 11:06:17 Encrypt 10.0.0.20:48778 10.0.1.8:14 4 sec 78 78 ICMP
2019-02-28 11:06:15 Encrypt 10.0.0.20:48776 10.0.1.8:14 4 sec 78 78 ICMP
2019-02-28 11:06:13 Encrypt 10.0.0.20:48777 10.0.1.8:14 1 sec 78 78 ICMP

The ICMP 78 bytes sent / 0 received continue for 3 minutes and then the pings start going through again (as does other traffic).

We also turned Heartbeats on and it shows no problems with the VPN.

The logs from the other side looks exactly the same with no problems except for the traffic stopping for 3 minutes after the rekey.

Any ideas?


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>