VPN Site to Site traffic stops

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

VPN Site to Site traffic stops

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
VPN Site to Site traffic stops
VPN Site to Site traffic stops
2025-04-08 03:20:12 - last edited 2025-04-09 07:35:13
Model: ER7206 (TL-ER7206)  
Hardware Version: V2
Firmware Version: 2.2.0 Build 20250218 Rel.17499

Using the Omada software controller, I've setup an IpSec / IKEv2 Site to Site VPN.

Omada ER7206 is the Responder;

A Draytek Vigor router - on VDSL - is the initiator.

 

The VPN connects and works perfectly as expected, but then randomly just stops routing traffic between LAN clients ('local' ER7206 to Remote).

 

When inter-LAN traffic stops, the remote LAN can still ping the Omada gateway LAN IP Address but not beyond to anything behind it.

The Omada LAN can ping the remote LAN gateway (Draytek IP) and beyond.

The VPN is setup to Route not NAT.

 

If I drop and reconnect the VPN, it starts working as expected again.

 

There is no indication at either end of any issues or drop of the VPN.  It is random and can occur any time between 1/2 hour and several hours.  I can't reproduce it at will.

 

Any thoughts on causes or where to look for such issues/logs etc?

 

Thanks,

Klaus
 

  0      
  0      
#1
Options
1 Accepted Solution
Re:VPN Site to Site traffic stops-Solution
2025-04-09 06:56:19 - last edited 2025-04-09 07:35:13

 

I may have found the issue and a solution (for some).
Noticed a duplicate connection from one site displaying the routing issue:

 

 

 

It would seem that the Draytek (as the initiator), for some reason, 'thought' the link was down and started another tunnel;

The Omada end accepted that 2nd tunnel without the first dropping;

Thus, a routing issue - eg which way out!

 

My solution to get around that was to reverse the establishment process, change Omada to Initiator and Draytek to accept Dial In.

Fortunately, I have all static public IPs

 

That's been up and working as expected for some time now.

 

 

Recommended Solution
  0  
  0  
#5
Options
4 Reply
Re:VPN Site to Site traffic stops
2025-04-08 06:24:14

Hi @Kadybee 

Thanks for posting in our business forum.

So, nothing has been changed lately on either side and this becomes noticeable?

Can you draw one for the community about your diagram?

Config screenshots as well.

It would be totally strange if you said it has no changes on both sites or the diagram and it suddenly becomes like this.

 

Please mosaic your sensitive information. Here is a list of information considered sensitive:

1. Public IP address on your WAN if your WAN is.

2. Real MAC address of your device.

3. Your personal information including address, domain name, and credentials.

For troubleshooting purposes, when a WAN IP is needed, please leave some values visible for identification.

  0  
  0  
#2
Options
Re:VPN Site to Site traffic stops
2025-04-08 10:31:29

  @Kadybee 

 

I have experienced similar issues with draytek routers being the dialling VPN initiator into TP-Link routers.  I would see DPD failures at random, strange connectivity like you are seeing etc.

 

If i remember right, I was able to mostly resolve it by changing the IPsec phase 1 and 2 encryptions to the "lowest" settings the draytek supported and changing the DPD timeout.  But i never fully resolved it.

 

 

Since i switched to TP link at remote site, the VPN is never problematic.  I think its a draytek issue.

  0  
  0  
#3
Options
Re:VPN Site to Site traffic stops
2025-04-08 12:35:59

  @GRL 

 

Thanks for that confirmation.  I suspected as much as the TP-Link Omada based sites VPNs are as solid as.  The only reason I went with the existing Drayteks was the VDSL connection and the lack of Omada in that.  Will switch the drayteks to bridge mode I guess and see where that takes me.

  0  
  0  
#4
Options
Re:VPN Site to Site traffic stops-Solution
2025-04-09 06:56:19 - last edited 2025-04-09 07:35:13

 

I may have found the issue and a solution (for some).
Noticed a duplicate connection from one site displaying the routing issue:

 

 

 

It would seem that the Draytek (as the initiator), for some reason, 'thought' the link was down and started another tunnel;

The Omada end accepted that 2nd tunnel without the first dropping;

Thus, a routing issue - eg which way out!

 

My solution to get around that was to reverse the establishment process, change Omada to Initiator and Draytek to accept Dial In.

Fortunately, I have all static public IPs

 

That's been up and working as expected for some time now.

 

 

Recommended Solution
  0  
  0  
#5
Options