Hej,
now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.
This thread was automatically locked due to age.
Hej,
now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.
Hi Bjoern, do you have any IKEv2 tunnels in place on 17GA and if so are they stable?
I too am extremely frustrated with this as most other firewalls have had IKEv2 for some time and don't have these ridiculous issues. I finally got my tunnel to Azure relatively stable and figured I'd update to MR2 and I'm back to the tunnel falling apart when it tries to rekey.
Starting to feel like we'll be babysitting these things forever waiting for the "next release" of firmware.
FIX THIS PLEASE!!!
Unfortunately, I don't have any IKEv2 tunnels yet. So many people are way behind on the VPN settings they use and that's why I haven't been able to implement that yet on the VPNs I manage and the firewalls that are on v17 with the described issues. Sorry to be no help in that case.
Hej Afschin,
thanks for your info. One setting of the policy was the problem. For me it was the setting "When Peer Unreachable". I set it to Disconnet and the policy was visible in "Respond Only" connections.
However, I still have problems with IPSec VPN connections with the "Authentication Type" "RSA Keys". Following message appears after some time in the charon.log:
INFORMATIONAL_V1 request with message ID 3198824668 processing failed
Afterwards I can't edit, delete, activate or deactivate the connections with RSA keys via the WebAdmin. Only a restart of the VPN service making them working again.
Thanks for the update. I have still been having some ipsec weirdness and am wondering if it will get to where I can trust it to be stable. I updated to MR-3 and it de-stabilized the tunnel again. I completely removed it and re-created it and it looks good. Unsure if I'll have to reconfigure every time there's an update.
XG to XG I think would be easier since it's easier to control the ike parameters. Connecting to Azure, AWS, etc. where you can't control the ipsec and ike parameters as well is where I've run into issues.
One solution for this would be to create a new vnet and create an XG virtual appliance to put the VM's behind - but there's significant effort overhauling your entire cloud infrastructure.
I'm still seeing some weirdness on MR-3 as well. It's definitely gotten better (we're about 95% of the way to a good connection), but I still see some weirdness with the IPSEC SA's not re-establishing themselves from time to time (I'm getting "ALERT: received IKE message with invalid SPI" occasionally)
In our case we're trying to run ipsec vpn between Sophos (has dsl connection(pppoe)) through a gre tunnel to a Cisco Router. Ugh....
-Scott
Yeah I get those and retransmission timeouts. Funny part is the only reason I jumped to v17 was for the IKEv2 support. Tunnel was working great on v16 with IKEv1. IKEv2 is needed for having failover tunnels with dual WAN links - haven't been able to set that up yet with all the troubleshooting of basic VPN connectivity :(
Just keep swimming...Just keep swimming...
Hi all
I have exactly the same troubles with v17 mrX.
I have several xg linking by IPsec vpn through pppoe xDSL connexions. Everything works great in v16.5 mr8.
When I update to v17, everything is broken, pppoe connexions never goes up, and/or IPsec vpn never goes up too.
I precise that I have deleted everything and recreate from scratch.
A downgrade to v16.5 mr8 and everything restarted well. I am fed up with those crappy v17 mrbeta.
if this is still the beta channel?!
I would also like to complain about this MR2 and MR3 release.
Why are these on the beta release because there is too much trouble with these releases.
No working IPSec and VPN,these complaints are also in GA, MR1, MR2 and MR3.
I hope there will be soon a stable beta release, I stop testing MR3 because too many bugs
Hope for Stable Release 1 on build 17 soon
17.1 (SR1)
Hey, I haven't done a downgrade but from what I gather I just need to upload the version 16 firmware and tell it to boot off of that correct? Is anything lost with the config?