Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP VPN Disconnects After 60 Minutes

Hey Folks,

I'm running the L2TP VPN Server, and I noticed that 60 minutes on the dot I will be disconnected. I did some searching on the Forums and Known Issues, and I discovered a past bug that was fixed for v7. Curious if perhaps it has reappeared in v8?


http://www.astaro.com/lists/Known_Issues-ASG-V7.txt

ID08349 7.200 L2TP connection terminates after 60 minutes
----------------------------------------------------------
Description:  Most L2TP connections are terminated after 60 minutes by the
              VPN backend. This mainly happens when some control packets
              are lost between client and server.
Workaround:   ---
Fix:          Fixed in 7.301


This thread was automatically locked due to age.
Parents
  • 2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: received Vendor ID payload [RFC 3947]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [4df37928e9fc4fd1b3262170d515c662]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [8f8d83826d246b6fc7a8a6a428c11de8]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [439b59f8ba676c4c7737ae22eab8f582]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [4d1e0e136deafa34c4f3ea9f02ec7285]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [80d0bb3def54565ee84645d4c85ce3ee]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [9909b64eed937c6573de52ace952fa6b]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: received Vendor ID payload [Dead Peer Detection]
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: responding to Main Mode from unknown peer 208.66.133.121:4500
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: NAT-Traversal: Result using RFC 3947: peer is NATed
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: Peer ID is ID_IPV4_ADDR: '172.18.10.225'
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: sent MR3, ISAKMP SA established
    2011:08:11-17:02:05 gateway pluto[12965]: "S_REF_xIQrjutFVk_1"[18] 208.66.133.121:4500 #62: received Delete SA payload: deleting ISAKMP State #62
    2011:08:11-17:02:05 gateway pluto[12965]: "S_REF_xIQrjutFVk_1"[18] 208.66.133.121:4500: deleting connection "S_REF_xIQrjutFVk_1" instance with peer 208.66.133.121 {isakmp=#0/ipsec=#0}
Reply
  • 2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: received Vendor ID payload [RFC 3947]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [4df37928e9fc4fd1b3262170d515c662]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [8f8d83826d246b6fc7a8a6a428c11de8]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [439b59f8ba676c4c7737ae22eab8f582]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [4d1e0e136deafa34c4f3ea9f02ec7285]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [80d0bb3def54565ee84645d4c85ce3ee]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [9909b64eed937c6573de52ace952fa6b]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: ignoring Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n]
    2011:08:11-17:02:00 gateway pluto[12965]: packet from 208.66.133.121:4500: received Vendor ID payload [Dead Peer Detection]
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: responding to Main Mode from unknown peer 208.66.133.121:4500
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: NAT-Traversal: Result using RFC 3947: peer is NATed
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: Peer ID is ID_IPV4_ADDR: '172.18.10.225'
    2011:08:11-17:02:00 gateway pluto[12965]: "S_REF_xIQrjutFVk_0"[14] 208.66.133.121:4500 #65: sent MR3, ISAKMP SA established
    2011:08:11-17:02:05 gateway pluto[12965]: "S_REF_xIQrjutFVk_1"[18] 208.66.133.121:4500 #62: received Delete SA payload: deleting ISAKMP State #62
    2011:08:11-17:02:05 gateway pluto[12965]: "S_REF_xIQrjutFVk_1"[18] 208.66.133.121:4500: deleting connection "S_REF_xIQrjutFVk_1" instance with peer 208.66.133.121 {isakmp=#0/ipsec=#0}
Children
No Data