• April 27, 2024, 12:55:22 PM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: DFL-210 L2L Tunnel Dropping  (Read 6263 times)

tylan

  • Level 1 Member
  • *
  • Posts: 12
DFL-210 L2L Tunnel Dropping
« on: September 16, 2009, 06:35:36 AM »

I have 2 DFL-210 Routers connected with a L2L tunnel.  I followed the documents on the Dlink FAQs.  The networks are 192.168.0.x and 192.168.100.x.  The users on the 192.168.100.x network connected via remote desktop to a server on the 192.168.0.x network.  They claim that the get kicked off daily.  Then they are able to get back on almost immediately.  I checked and the router has not been rebooted / shutdown recently.  I think that they are getting kicked off when the tunnels re-negotiate.  I sent the configs to dlink a few months back when they initially complained.  Dlink found nothing wrong.  Can I up the time the tunnels go w/o re-negotiating?  Is there anything else I can check?

Any ideas?

Tylan
Logged

tylan

  • Level 1 Member
  • *
  • Posts: 12
Re: DFL-210 L2L Tunnel Dropping
« Reply #1 on: September 21, 2009, 07:22:41 AM »

I may have phrased my post in a complicated paragraph...

Here's what I'm really looking for:
1) When a L2L tunnel renegotiates daily, would the connections through the tunnel be interrupted?

2) Can I up the time a tunnel stays alive so that this issue could be avoided?

Thanks in advance!
Tylan
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: DFL-210 L2L Tunnel Dropping
« Reply #2 on: September 21, 2009, 09:15:00 AM »

Sessions ideally should not be dropped when renigotiations happens, assuming it goes through without a hitch.

What are your timeouts?
Do you have a data based timeout?
Do you use a keep alive?
Do you use DPD?
Logged
non progredi est regredi

tylan

  • Level 1 Member
  • *
  • Posts: 12
Re: DFL-210 L2L Tunnel Dropping
« Reply #3 on: September 22, 2009, 08:55:51 AM »

--IKE Lifetime 28800
--IPSEC Lifetime 3600
--Keep-alive set to auto

I'm not sure what you mean by DPD or data based timeout...  Sorry.

Here is the doc I used to configure the tunnels:
http://www.dlink.com/support/faqDetail/?prod_id=2783&print=1

Thanks for your reply,
Tylan
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: DFL-210 L2L Tunnel Dropping
« Reply #4 on: September 22, 2009, 09:26:45 AM »

DPD Is a setting on the IKE tab.

Data based timeout referred to an IPsec lifetime based on a number of kilobytes.

I believe this document will be revised in the near future, if followed perfectly it could cause some problems.  Specifically you are going to have 2 routing entries for the same tunnel which could be causing your problem.

Uncheck the box that says Dynamically add route to the remote network when a tunnel is established.
Logged
non progredi est regredi

tylan

  • Level 1 Member
  • *
  • Posts: 12
Re: DFL-210 L2L Tunnel Dropping
« Reply #5 on: September 22, 2009, 09:47:20 AM »

--DPD is checked.
--The IPSEC lifetime is set to 0 kilobytes.

I don't see any duplicate routes in the routing table.  Are you referring to a duplicate route that doesn't actually show in the tables.  I'd post a screenshot, but I'm not sure how to do it.
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: DFL-210 L2L Tunnel Dropping
« Reply #6 on: September 22, 2009, 10:11:06 AM »

Eureka!

DPD (Dead Peer Detection) is the mortal enemy of Keep Alive, using both at once is a problem of sizeable scale.  Since you don't want your tunnel going down ever remove DPD.

You would see it in Status->Routes, but only while the tunnel is up.  A better place to check would be if you have both that check box, and the automatically add route box on the advanced tab checked.

As this is a L2L installation you should have the one on the advanced tab only and not the one on the routing tab.
Logged
non progredi est regredi

tylan

  • Level 1 Member
  • *
  • Posts: 12
Re: DFL-210 L2L Tunnel Dropping
« Reply #7 on: September 22, 2009, 02:57:03 PM »

I see what you are talking about now.  There are two settings about adding the route.  I cleared the dynamic add route box on the routing tab, and left the one on the advanced tab checked.  I also cleared the dead peer detection box.

Anything else I should check, or just sit back and wait for the customer to NOT complain about the tunnel dropping!

Thanks
Logged

Fatman

  • Level 9 Member
  • ****
  • Posts: 1675
Re: DFL-210 L2L Tunnel Dropping
« Reply #8 on: September 22, 2009, 03:27:02 PM »

Well lets hope it is sitting back and waiting for the customer to not complain.
Logged
non progredi est regredi

tylan

  • Level 1 Member
  • *
  • Posts: 12
Re: DFL-210 L2L Tunnel Dropping
« Reply #9 on: September 22, 2009, 05:05:40 PM »

Then I'll inform them that I've adjusted some settings on the L2L Tunnel and we'll see what happens.

Thanks,
Tylan
Logged