A new variant of an old issue - VPN profiles gone horribly wrong

A new variant of an old issue - VPN profiles gone horribly wrong

A new variant of an old issue - VPN profiles gone horribly wrong
A new variant of an old issue - VPN profiles gone horribly wrong
Monday - last edited Tuesday

@Vincent-TP 

 

OC300, 1.30.7

 

IF you cast your mind back to when 5.14 and 5.15 were first in Beta and release stages there was a persistent issue with VPN profiles disappearing but still active on the gateways.  This seemed to be fixed with the later beta's and releases of 5.15

 

Tonight, i had a new variant of this!

 

I had need to change which WAN ports my VPN profiles were active on.  So, taking the lazy approach, i simply edited each profile to change the active WAN port on each one.  I had to juggle them around to different ports to eventually swap all the ones from WAN 4 to WAN 6, and the ones from WAN 6 to WAN 4 on my ER8411

 

After i had swapped them all around, and the gateway (ER8411) finished configuring, i gave it all a reboot for good measure

 

All the VPN profiles were working EXCEPT the one for the remote sites.  The profile was still visible, just none of the sites would connect.  I double and triple checked the actual VPN settings - all good.

 

I factory reset the gateway thinking a fresh adoption and configure would jolt it - no success

I took a backup and factory reset / restored the backup on the OC300 thinking maybe it didnt push the configs to the Gateway - no success

 

The only way i was able to fix it was to actually delete all the VPN profiles save a OC300 backup, factory reset the OC300, restore OC300 Backup without any VPN profiles, Factory reset ER8411, let the gateway reconfigure, then make every single VPN pforile from scratch.  Everything immediately worked, all remote sites connected.

 

The best i can figure it - the profile was fine and visible, but when moving the WAN ports they are set to, somehow the controller didnt push this to the gateway - even after a gateway re-adopt.

 

Since everything has been factory reset i unfortunately dont think there are any useful logs i can pull for you.  Perhaps you can replicate this internally.

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0      
  0      
#1
Options
5 Reply
Re:A new variant of an old issue - VPN profiles gone horribly wrong
Tuesday

Hi  @GRL 

 

Thanks for posting here. To avoid any miunderstanding, please help me to understand the following:

1. So, taking the lazy approach, i simply edited each profile to change the active WAN port on each one.  I had to juggle them around to different ports to eventually swap all the ones from WAN 4 to WAN 6, and the ones from WAN 6 to WAN 4 on my ER8411

 

>>>Do you mean select a differen WAN port on this page and apply the config?

 

 

2. All the VPN profiles were working EXCEPT the one for the remote sites.  

>>> What's does the one for the  remote sites mean? 

Are you referring to the VPN profiles that used to establish site-to-site VPN connections between remote devices?

For example:

An IPsec VPN tunnel created between an ER8411 and ER7206
After this setup, did the ER7206 and its site devices turn to Disconnected from the controller?

 

 

  0  
  0  
#2
Options
Re:A new variant of an old issue - VPN profiles gone horribly wrong
Tuesday - last edited Yesterday

  @Vincent-TP 

 

Yes, correct - changing the WAN port there

 

After  i swapped them all, all of my Client-to-site VPNs worked.  However, the one that went badly wrong was a IPsec Site-to-Site, and acting as the responder.  Therefore, all the remote sites (ER605 v2 in this case) went disconnected.  I had already changed the target IP of each remote sites VPN so they should, in theory have just reconnected immediately.

 

The VPN status page also didnt list any connections of that particular profile either

 

They only reconnected after all the faffing about i had to do.

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#3
Options
Re:A new variant of an old issue - VPN profiles gone horribly wrong
Yesterday

Hi  @GRL 

Thank you for the confirmation.

Please send us the latest configuration file for the controller for testing via the case TKID250903890.

  0  
  0  
#4
Options
Re:A new variant of an old issue - VPN profiles gone horribly wrong
Yesterday

  @Vincent-TP 

 

Done, thank you

 

Like i said, this may have been a one off glitch my end, but always worth raising these things!

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#5
Options
Re:A new variant of an old issue - VPN profiles gone horribly wrong
Yesterday - last edited Yesterday

  @GRL 

 

but always worth raising these things!

 

>>>This is always highly appreciated!

  0  
  0  
#6
Options