ER605 2.3.3 Problems with SIP and ping through IpSec VPN tunnel

ER605 2.3.3 Problems with SIP and ping through IpSec VPN tunnel

ER605 2.3.3 Problems with SIP and ping through IpSec VPN tunnel
ER605 2.3.3 Problems with SIP and ping through IpSec VPN tunnel
17 hours ago - last edited 2 hours ago
Tags: #VPN
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.3

I do have a problem with ER605v2 2.3.3 and IPSec VPN traffic. When there is a traffic through VPN during the router boot, the traffic is blocked permanently.


The issue goes as follows:

1) From the LAN behind ER605 I have connections through IPSec VPN to another LAN

- Active SIP connection to the server in another LAN.

- active ping from a computer to IP in another LAN

2) Rebooting the ER605

3) VPN connects and there is a connection to anything in the remote LAN except:

- The SIP connection does not work. Registration to the SIP server in remote LAN fails. Http connection to the same IP works correctly. In the same time the device registers to the SIP service in the internet using the WAN and NAT.

- ping active during the reboot still shows no response. But, the SMB connection the the same IP works correctly. Also, I can ping any other IP in the remote LAN just fine.


By my understanding there is some function permanently blocking UDP IPv4 traffic if it is active during ER605 boot sequence.


There are a few configuration detail that could have some impact, or perhas are completely irrelevant in this issue.

- ER605 is set up in dual WAN mode, but the second WAN is not connected.

- The LAN is a bit complicated. Directly behind the ER605 there is 192.168.121.1  255.255.255.192 LAN and two other LANs behind another router 192.168.121.64 255.255.255.192 and  192.168.121.128  255.255.255.128.

  0      
  0      
#1
Options
2 Reply
Re:ER605 2.3.3 Problems with SIP and ping through IpSec VPN tunnel
15 hours ago - last edited 15 hours ago

  @For-Soft 

 

A little confused...  the phones don't reconnect to the SIP server, after a reboot is complete? Does it work after the reboot is completed?  

 

There should be a retry/timeout setting on the phone and OR the PBX.  

I can not teach anyone anything - I can only make them think - Socrates
  0  
  0  
#2
Options
Re:ER605 2.3.3 Problems with SIP and ping through IpSec VPN tunnel
13 hours ago

No, that's not the case. The VPN reconnects, and evertyhing TCP based works correctly.

 

On the other hand, the communication with SIP server is broken. If I manually force the reconnection, it does not work. The workaround for problems with SIP serwer is:

- turn off the phone, so there is no SIP traffic through VPN

- reboot the ER605

- wait for the IPSec tunnel to reconnect

- turn on the phone

Then the phone connects to the SIP server through VPN.

 

The pings running during the reboot are showing no connection. But, a new ping started to a different address in the remote LAN, after tunnel reconnects, works fine.

  0  
  0  
#3
Options