This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Release of v17 MR-2?

Hej,

now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.



This thread was automatically locked due to age.
Parents
  • Support has sent me a couple of new things to try. I'm waiting to get some time scheduled with the network engineer on the other end to try them out, but thought someone else might be able to test them before I get to. Here's what they said.

     

    The lifetimes need to be set to Phase1: 10800 and Phase2: 3600

    If you are using SHA2 you have to select the option for 96-bit truncation

     

    In my case I'm not using SHA2, so that's not my issue, but it might help someone else. I'm curious to see if the lifetime settings have any effect.

    In the meantime I have brought a decommissioned ASA back online in our network and have removed the affected tunnel from our XG and am now running it off of that. I'll continue testing because I'd like to just have the XG if possible. This issue has been so aggravating....

Reply
  • Support has sent me a couple of new things to try. I'm waiting to get some time scheduled with the network engineer on the other end to try them out, but thought someone else might be able to test them before I get to. Here's what they said.

     

    The lifetimes need to be set to Phase1: 10800 and Phase2: 3600

    If you are using SHA2 you have to select the option for 96-bit truncation

     

    In my case I'm not using SHA2, so that's not my issue, but it might help someone else. I'm curious to see if the lifetime settings have any effect.

    In the meantime I have brought a decommissioned ASA back online in our network and have removed the affected tunnel from our XG and am now running it off of that. I'll continue testing because I'd like to just have the XG if possible. This issue has been so aggravating....

Children
  • Support set me up with phase 1 28800 (not 10800 like they told you) and phase 2 3600 even though that's not what the ASA was at for either ph1 or ph2. Ikev1. They remoted in and made a new one for me using the prebuilt remote office template. With this, the best I ever got was for it to stay up for 1 week, and that was a huge improvement, but as soon as my constant ping PC pinging the other side day and night had to reboot, tunnel between xg105 and ASA never stayed up again after that. The key life settings did not at all match the ASA. but matching them didn't help at all so, I welcomed the change.
  • None of the config above would work with azure. Maybe aws.