DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

IPSec VPN Drops connection after an hour

  • themonk
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
04 Feb 2010 00:45 #60321 by themonk
I have a IPSec VPN setup between a 2910VG ans 2820, all connects and runs fine except that the VPN drops and then connects every hour.

The 2910 dials out to the 2820 so I have 'Always On' checked and 'Enable ping to keep alive' on the 2910 and on the 2820 I've set 'Idle Timeout 0'.

Any thoughts as to why it does this and is there a solution?
Thanks.

Please Log in or Create an account to join the conversation.

More
04 Feb 2010 12:24 #60325 by njh
Have you checked your Key Lifes at each end? I think it is in the advanced section of the LAN-LAN IPSec set up. Make sure they match.

2900Gi/v2.5.6; 2900/v2.5.6

Please Log in or Create an account to join the conversation.

  • themonk
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
04 Feb 2010 20:07 #60339 by themonk
Replied by themonk on topic IPSec VPN Drops connection after an hour
Yes, running in aggressive mode.
IKE phase 1 key lifetime = 86400
IKE phase 2 key lifetime = 3600
PFS to Disable.

Not sure what else to check.

Please Log in or Create an account to join the conversation.

More
04 Feb 2010 20:44 #60340 by njh
I'm not sure what to check either. It may be worth looking at firmware updates and see what has changed recently.

You should not need the ping to keep alive.

As a side issue, for security, I'd disable aggressive mode and enable PFS. Any reason why you have chosen the other way round?

2900Gi/v2.5.6; 2900/v2.5.6

Please Log in or Create an account to join the conversation.

  • themonk
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
04 Feb 2010 21:53 #60342 by themonk
Replied by themonk on topic IPSec VPN Drops connection after an hour
I'm using Aggressive as the connection is from a dynamic IP to a static also slightly faster connection. I've changed the IKE phase 2 Key Lifetime to 43200 (12 hours) and so far the connection has held up.

Please Log in or Create an account to join the conversation.

More
04 Feb 2010 22:16 #60344 by njh

themonk wrote: I'm using Aggressive as the connection is from a dynamic IP to a static also slightly faster connection.

.... at the expense of security. Dynamic to Static does not need agressive mode. Also if you manage to fix the problem your connection should be rock solid so the speed which you make the connection becomes pretty irrelevant.

I've changed the IKE phase 2 Key Lifetime to 43200 (12 hours) and so far the connection has held up.

Probably just delaying the inevitable. Also security ........

Which revisions of firmware are using?

2900Gi/v2.5.6; 2900/v2.5.6

Please Log in or Create an account to join the conversation.

Moderators: ChrisSami