SD-WAN disconnected - had to reboot both gateways to bring the connection back

SD-WAN disconnected - had to reboot both gateways to bring the connection back

SD-WAN disconnected - had to reboot both gateways to bring the connection back
SD-WAN disconnected - had to reboot both gateways to bring the connection back
a week ago - last edited Yesterday
Tags: #SD-WAN
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0 Build 20250428 Rel.18967

hi all,

 

today I've experienced another SD-WAN issue - it was disconnected without usual recovery.

Normally, when my ISP reboots my xDSL modem, I get new public IP address and the SD-WAN connection will be restored. In eventlog there is a following message: [Failed]WAN1: DPD detection times out. IPsec connection was disconnected.

 

Today, no recovery occurred and I had to reboot both gateways, where the one on other site (primary is the one with controller) was not able even to display the login web page and has to be powercycled.

 

Anyone had experienced such situation?

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0      
  0      
#1
Options
1 Accepted Solution
Re:SD-WAN disconnected - had to reboot both gateways to bring the connection back-Solution
Yesterday - last edited Yesterday

  @ZoloNN 

Thank you for your post. Has the issue you encountered reoccurred since then? If so, how frequently does it happen? According to the logs, the connection timed out because DPD (Dead Peer Detection) packets received no response, which appears to be the primary cause. You may need to verify whether your ISP connection is stable or if any settings are blocking the connection.

Recommended Solution
  0  
  0  
#2
Options
4 Reply
Re:SD-WAN disconnected - had to reboot both gateways to bring the connection back-Solution
Yesterday - last edited Yesterday

  @ZoloNN 

Thank you for your post. Has the issue you encountered reoccurred since then? If so, how frequently does it happen? According to the logs, the connection timed out because DPD (Dead Peer Detection) packets received no response, which appears to be the primary cause. You may need to verify whether your ISP connection is stable or if any settings are blocking the connection.

Recommended Solution
  0  
  0  
#2
Options
Re:SD-WAN disconnected - had to reboot both gateways to bring the connection back
Yesterday

  @ZoloNN 

 

If you switch from SD-WAN to IPSec (but will have to build all the inter-site VPNs manually) you can change the DPD timeout or disable it entirely which might help with this situation

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#3
Options
Re:SD-WAN disconnected - had to reboot both gateways to bring the connection back
Yesterday - last edited Yesterday

Hi @Ethan-TP,

 

On one site I have (semi)permanent public IP address (DHCP lease is renewed with the same IP except when the ISP makes some maintenance) on FTTH.

On the other site my public IP changes quite frequently as my ISP reboots the xDSL modem appoximately once a week with foolish excuse of "purging the DHCP pool laugh.

 

Usually the SD-WAN resync without problem, but in this case it was different. the SD-WAN died without the usual public IP change (I monitor the availability of "8.8.8.8" via KUMA) and that's the reason behind my question. It happened already the second time, that I had to reboot both gateways to bring the connection back.

 

for the reference: this was the first and more severe SD-WAN outage

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0  
  0  
#4
Options
Re:SD-WAN disconnected - had to reboot both gateways to bring the connection back
Yesterday

Hi @GRL,

 

this is my 3rd site2site VPN solution in place.

 * The first one was OpenVPN connection using my previous Asus RT-AC66N_B1 routers running Merlin firmware.

 * Second one (as I wasn't satisfied with the speed) was based on virtualised pfSense using WireGuard

Then I've replaced my Asus routers (which support cycle has ended) with ER605 gateway but unfortunately till FW 2.3.0 the peer configuration accepted only IP address and no FQDN - so I stayed with the pfSense setup. This was robust and I haven't experienced any connection outages (of course except internet connectivity outages wink).

* Then the FW 2.3.0 was released. First, I wanted to move the WireGuard setup from pfSense to ER605, but the SD-WAN easy setup has surprised me and I've choose it as my third one.

 

Maybe I'll return to WireGuard site2site setup when the troubles with SD-WAN will continue to happen.

 

/BR ZoloNN ----------------------------------------------------------------------------------- Omada 2x ER605(UN) v2.0 + SG2008P(UN) V3.20 + SG2218 V1.20 + 2x SG2008 V4.20 + 3x EAP615-Wall(EU) V1.0
  0  
  0  
#5
Options