ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Unsolved site to site VPN only works with Keep Alive

    IT Discussion
    5
    23
    1.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      You only need a keep alive when you have no traffic. But, not having traffic can happen simply from everyone going to lunch at the same time.

      1 Reply Last reply Reply Quote 1
      • Mike DavisM
        Mike Davis
        last edited by

        It's really odd. I had a continuous ping going as I was changing settings. At some point I checked the box and all the sudden I started getting replies. I kept checking and unchecking boxes until I found that that was the thing that was doing it. As soon as I turn it off, the connection drops, even though there should be a continuous ping going across the connection.

        NetworkNerdN 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          That is odd, not sure why that would be. KA should only affect you after a few minutes, at least, often more than that.

          1 Reply Last reply Reply Quote 0
          • NetworkNerdN
            NetworkNerd @Mike Davis
            last edited by NetworkNerd

            @mike-davis said in site to site VPN only works with Keep Alive:

            It's really odd. I had a continuous ping going as I was changing settings. At some point I checked the box and all the sudden I started getting replies. I kept checking and unchecking boxes until I found that that was the thing that was doing it. As soon as I turn it off, the connection drops, even though there should be a continuous ping going across the connection.

            Man, this sounds really odd like the issue I had with a Cisco ASA and a Meraki device, especially the part about the tunnel dropping. I know it's not the same scenario here, but this one peaked my curiosity and gave me a touch of deja vu.

            I wonder if Sonicwall Support can explain it?

            Mike DavisM 1 Reply Last reply Reply Quote 1
            • Mike DavisM
              Mike Davis @NetworkNerd
              last edited by

              @networknerd said in site to site VPN only works with Keep Alive:

              I wonder if Sonicwall Support can explain it?

              The reason I was getting this tunnel going is I'm swapping out the current SonicWall that is falling out of support for one that is under support. Once I get the one under support on a live network, I can contact support.

              dbeatoD 1 Reply Last reply Reply Quote 0
              • dbeatoD
                dbeato @Mike Davis
                last edited by

                @mike-davis Keep Alive is something I have enabled on all Sonicwalls for that reason. Otherwise on networks that there is no continual traffic it will stop. Cisco is notorious for this, so I have a continual ping a on a server between Cisco and AMazon. Same for SonicwALL with Network Monitor (another solution) with the Amazon VPC tunnels.

                1 Reply Last reply Reply Quote 1
                • Mike DavisM
                  Mike Davis
                  last edited by

                  It's really odd because I have an existing tunnel that has been up for 2 years with no issues on that same SonicWall and it doesn't have the keep alive enabled.

                  dbeatoD 1 Reply Last reply Reply Quote 0
                  • dbeatoD
                    dbeato @Mike Davis
                    last edited by

                    @mike-davis What firmware are you on?

                    Mike DavisM 1 Reply Last reply Reply Quote 0
                    • Mike DavisM
                      Mike Davis @dbeato
                      last edited by

                      @dbeato said in site to site VPN only works with Keep Alive:

                      @mike-davis What firmware are you on?

                      5.9.0.7-17o on the remote side for my test environment. That will be swapped out for one under support. My issue is that I don't have the password to the production one, so my only option is to factory default it and I wanted to make sure if I did, I could get the tunnel back up.

                      The main is is current firmware since it's under support.

                      dbeatoD 2 Replies Last reply Reply Quote 0
                      • dbeatoD
                        dbeato @Mike Davis
                        last edited by

                        @mike-davis said in site to site VPN only works with Keep Alive:

                        5.9.0.7-17o

                        That is a pretty old firmware. Update to the latest 5.9.1.7 and 5.9.1.8.

                        Mike DavisM 1 Reply Last reply Reply Quote 1
                        • Mike DavisM
                          Mike Davis @dbeato
                          last edited by

                          @dbeato said in site to site VPN only works with Keep Alive:

                          @mike-davis said in site to site VPN only works with Keep Alive:

                          5.9.0.7-17o

                          That is a pretty old firmware. Update to the latest 5.9.1.7 and 5.9.1.8.

                          I totally forgot about that. Like I said, this was a spare one I had on hand for testing and I wanted to make sure I could get the tunnel up when I factory reset the one under support since I can't log in to see its settings.

                          dbeatoD 1 Reply Last reply Reply Quote 1
                          • dbeatoD
                            dbeato @Mike Davis
                            last edited by

                            @mike-davis You also can still download Early releases and they do work well too.

                            1 Reply Last reply Reply Quote 0
                            • dbeatoD
                              dbeato @Mike Davis
                              last edited by

                              @mike-davis said in site to site VPN only works with Keep Alive:

                              about that. Like I said, this was a spare one I had on hand for testing and I wanted to make sure I could get the tunnel up when I factory reset the one under support since I can't log in to see its settings.

                              Make a backup also of the settings as well just in case.

                              1 Reply Last reply Reply Quote 2
                              • dbeatoD
                                dbeato
                                last edited by

                                @Mike-Davis How did you end up working out this one?

                                Mike DavisM 1 Reply Last reply Reply Quote 1
                                • iroalI
                                  iroal
                                  last edited by

                                  This was one of the reasons we leave sonicwall in the company, apart of the support cost.

                                  Now with Pfsense using VpnSite all problems disappears.

                                  Mike DavisM 1 Reply Last reply Reply Quote 2
                                  • Mike DavisM
                                    Mike Davis @dbeato
                                    last edited by

                                    @dbeato said in site to site VPN only works with Keep Alive:

                                    @Mike-Davis How did you end up working out this one?

                                    I think I left it with the keep alive going and the static IP on both ends.

                                    dbeatoD 1 Reply Last reply Reply Quote 1
                                    • Mike DavisM
                                      Mike Davis @iroal
                                      last edited by

                                      @iroal said in site to site VPN only works with Keep Alive:

                                      This was one of the reasons we leave sonicwall in the company, apart of the support cost.
                                      Now with Pfsense using VpnSite all problems disappears.

                                      My first choice is Ubiquiti. In this case the Sonics came in under grant money and I had to use them.

                                      scottalanmillerS 1 Reply Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller @Mike Davis
                                        last edited by

                                        @mike-davis said in site to site VPN only works with Keep Alive:

                                        @iroal said in site to site VPN only works with Keep Alive:

                                        This was one of the reasons we leave sonicwall in the company, apart of the support cost.
                                        Now with Pfsense using VpnSite all problems disappears.

                                        My first choice is Ubiquiti. In this case the Sonics came in under grant money and I had to use them.

                                        Even with grant money, not sure that they are worth it 😉

                                        1 Reply Last reply Reply Quote 0
                                        • Mike DavisM
                                          Mike Davis
                                          last edited by

                                          I really don't like grant money. It sounds like a good idea, but when you actually see how it works, it's such a waste. As a tax payer I would like to see the system changed. As a tax payer, I would rather see ubiquiti gear and OpenDNS go in than a SonicWall with content filtering and VPN licenses.

                                          scottalanmillerS 1 Reply Last reply Reply Quote 1
                                          • scottalanmillerS
                                            scottalanmiller @Mike Davis
                                            last edited by

                                            @mike-davis said in site to site VPN only works with Keep Alive:

                                            I really don't like grant money. It sounds like a good idea, but when you actually see how it works, it's such a waste. As a tax payer I would like to see the system changed. As a tax payer, I would rather see ubiquiti gear and OpenDNS go in than a SonicWall with content filtering and VPN licenses.

                                            Oh yeah. As a tax payer all I see is open corruption. SonicWall is getting tax dollars funneled straight to them. No possible ethical reason for a real grant to exist only to fund a private company.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post