cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
15083
Views
0
Helpful
21
Replies

rv042 vpn dropped

jcsoucy01
Level 1
Level 1

Hi

Sometime we have a problem with some custumers with a  (all day  and don’t reconnect automatiquely). We’ve try many configuration and update, mtu size, new rv042 and it’s don’t resolve the problem

Other custumers  have this problem but  one time in a mouth or 2 or 3 mouth.

We’ve trying other router from another brand and resolve the problem in one place. We don’t want to change all custumers for the new router we want to keep rv042 because we like it and about 60 was install in many place.

Thanks for your help

21 Replies 21

Would you please call into the Small Business Support team so we can gather more information on your environment in order to root cause the issue?

Pierre,

If you current configuration is still the same as in the screenshot you posted, enable aggressive mode on the side whose "Remote Group" is based on FQDN. This allows a little more time for the tunnel to establish and also to reconnect should it go down. Also if possible please post the VPN log eventhough the log may not say that the tunnel is down. One thing that I have noticed is that if the units time is not correct we experience what you are describing (dont know why). I would be willing to bet that your VPN log will show a constant state of authentication over and over, and you would probably see ISAKMP key expiration, followed by renegotiation. Please keep us posted.

Remember that posts like yours allows us to find resolutions to problems based on FW releases or configuration. They do get noticed.

Hi,

After few experiences, what I can say is : the last firmware (1.3.12.19-tm) is the worst one ever made for the RV042 (I'm sorry but I'm really becoming enough of all problems with this router...).

Few explains :

Actually the bigest problem is not to have a stable VPN but to have a VPN where all data go through inside.

I tried lot of configurations and in almost all cases I could get a VPN connected and I could ping the next router (trough the VPN). But if I'm doing a data transfert or a Remote Desktop on my TSE server : almost all data are lost. => VPN totaly unusable !

I finaly found a temporary working solution : I changed the MTU from auto to 1490 (my connection is normaly 1492 but it's the maximum value with I could get with fully working VPN). And I did a basic Gateway-to-Gateway VPN (see the screenshot 1). In this case I can use a Remote Desktop and do data transfert.

Few days after I tried to make the VPN more secure, so I decided to change the configuration (see the screenshot 2). The VPN get connected but same problem as before, impossible to do data transfert or RDP. I tried to change the MTU untill the value 1200 but still nothing is going normaly. I finaly roll back to the last working configuration...

I read on internet that I'm not alone to have a MTU issue. Cisco must do something quickly. Very bad publicity for you, and very bad for all RV042 users...

Thanks !

Hi,

I get this error too with my site-to-site VPN.

In central office Keep Alive, NAT Traversal and DPD is activated.

In remote office Agressive mode, NAT Traversal and DPD is activated.

VPN is goes down and after few seconds goes up.

This is the log from RV042 from central office:

Nov 26 14:38:50 2009    VPN Log   ignoring Delete SA payload: IPSEC SA not found (maybe expired)
Nov 26 14:38:50 2009    VPN Log   ignoring Delete SA payload: IPSEC SA not found (maybe expired)
Nov 26 14:38:50 2009    VPN Log   ignoring Delete SA payload: IPSEC SA not found (maybe expired)
Nov 26 14:38:50 2009    VPN Log   ignoring Delete SA payload: IPSEC SA not found (maybe expired)
Nov 26 14:38:50 2009    VPN Log   Dead Peer Detection Start, DPD delay timer=10 sec  timeout=10 sec
Nov 26 14:38:50 2009    VPN Log   [Tunnel Negotiation Info] Quick Mode Phase 2 SA Established, IPSec Tunnel Connected
Nov 26 14:38:50 2009    VPN Log   [Tunnel Negotiation Info] >>> Initiator Send Quick Mode 3rd packet
Nov 26 14:38:50 2009    VPN Log   [Tunnel Negotiation Info] Outbound SPI value = 71a9ceb5
Nov 26 14:38:50 2009    VPN Log   [Tunnel Negotiation Info] Inbound  SPI value = d7661b0f
Nov 26 14:38:50 2009    VPN Log   [Tunnel Negotiation Info] <<< Initiator Received Quick Mode 2nd packet
Nov 26 14:38:49 2009    VPN Log   [Tunnel Negotiation Info] >>> Initiator send Quick Mode 1st packet
Nov 26 14:38:49 2009    VPN Log   initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+NAT-T to replace #589

Software version on both routers is                  1.3.12.6-tm. We had no problem with connectivity between sites in this time.

daviddun
Level 3
Level 3

Good Morning,

Please call into the SBSC 1.866.606.1866 for support on this problem.  The first steps after you have upgraded the firmware on both sides is to do a factory reset to the units.

After the reset, then setup your tunnels, if you have any problems then you need to call in for support.

I followed your advise, I did a hard reset on both RV042 (firmware 1.3.12.19tm) and, it broke everything.

Now I still have an unstable VPN but the worst thing is I have also a MTU problem on the vpn (maximum size I can get is 1412bytes with ping -f -l 1412). This is a big problem because I we are using TSE on the tunnel and with this new MTU problem it's impossible to use TSE...


I read on internet I'm not alone to have MTU problem (but most of people are getting this problem on the internet connection and not on the vpn).


Do cisco I working on a new firmware? Do there is a solution? Where can I get a older firmware? Where should I call to report this problem (I'm in France).


Thanks

Here are the contact information for france, I am not sure which one of these contact numbers you would need to use, so I posted them all.  Hopefully this helps you out.

France

Cisco Systems France
11, rue Camille Desmoulins
92782 Issy les Moulineaux
Cedex 9, France
Phone: 0 800 770 400
+33(0)1 58 04 58 58
Fax: +33 (0)1 58 04 61 00

Cisco Systems France
Immeuble Danica
21 av. Georges Pompidou
La Part Dieu
69486 Lyon Cedex 03, France
Phone: 0800 770 400
+33(0)1 58 04 58 58
Fax: +33(0)4 72 91 30 30

Cisco Systems France
Centre d'Affaires d'Alizés
La Rigourdière
35510 Cesson Sevigné, France
Phone: 0 800 770 400
+33(0)1 58 04 58 58
Fax: +33(0)2 99 83 53 54


Cisco Systems France
Regus Centre
8, Esplanade Compans Caffarelli
31 000 Toulouse, France
Phone: 0800 770 400
+33(0)1 58 04 58 58
Fax: +33 (0)5 62 30 50 00

Cisco Systems France
Place des Halles
Tour Sebastopol, Bureau 313
3, quai Kleber
67080 Strasbourg cedex 3, France
Phone: 0800 770 400
+33(0)1 58 04 58 58
Fax: +33(0)3 88 23 70 00

Cisco Sophia Antipolis
Village d'Entreprises Green Side
400, avenue Roumanille
bâtiment 3
06410 Biot, France
Phone: 0 800 770 400
+33(0)1 58 04 58 58
Fax: +33(0)4 97 23 26 26

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: