DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Load Balance IPSec Tunnels not connecting / dropping.
- m_d
- Topic Author
- Away
- New Member
Less
More
- Posts: 9
- Thank yous received: 0
30 Jan 2025 19:18 - 30 Jan 2025 19:24 #104516
by m_d
Load Balance IPSec Tunnels not connecting / dropping. was created by m_d
I have had an IPSec VPN running reliably between a Vigor 2860 and a Vigor 2865 for some time. The 2860 dials out, and the 2865 is configured for dial in. However, slight complication, the remote Vigor 2860 has two WAN connections: a very slow VDSL line, and a faster but unreliable LTE connection. So, I disabled the 'old' VPN connection, and setup two new LAN-2-LAN profiles with GRE / IPSec, setup in load balance mode, as per this guide:
https://www.draytek.com/support/knowledge-base/4919
.
The idea is that the Vigor 2860 will dial two VPN connections, 1 through VDSL and the other through LTE which will both connect to the 2865 through a single WAN connection. I can then setup routing policy rules to send some traffic via VDSL and some via LTE at the remote site. This did work when initially setup, however after running fine for a bit, these VPN's seem to get into the following state:
- ONE of the two VPN connections comes up successfully. BUT, it drops & re-connects every 20-60 ish seconds.
- The other one of the two connections refuses to come online.
In this state, the Web Syslog shows the following messages on the Dial-Out end (Vigor 2860):
And on the Dial-In end (Vigor 2865):
I know the timestamps don't quite match there, this is just because the web syslog on the Dial-In router had overwritten the entries by the time I copied the logs.
I have had success rebooting one or both ends of the tunnel, which sorts the problem out for a time, but then the same thing occurs.
Apologies if that is not quite clear, can provide any more details if required. Would really appreciate any suggestions.
The idea is that the Vigor 2860 will dial two VPN connections, 1 through VDSL and the other through LTE which will both connect to the 2865 through a single WAN connection. I can then setup routing policy rules to send some traffic via VDSL and some via LTE at the remote site. This did work when initially setup, however after running fine for a bit, these VPN's seem to get into the following state:
- ONE of the two VPN connections comes up successfully. BUT, it drops & re-connects every 20-60 ish seconds.
- The other one of the two connections refuses to come online.
In this state, the Web Syslog shows the following messages on the Dial-Out end (Vigor 2860):
Code:
2025-01-30 19:08:36 Dialing Node8 (VPN_2) :
2025-01-30 19:08:36 Find phase1 state #1809, peer IP address x6.1.1x3.x6 port 4500
2025-01-30 19:08:36 ## IKEv2 DBG : CHILD SA outI1 : Initiate CHILD SA #1812 , IKESA is #1809
2025-01-30 19:08:49 [IPSEC][L2L][8:VPN_2][@x6.1.1x3.x6] IKE link timeout: state linking
And on the Dial-In end (Vigor 2865):
Code:
2025-01-30 19:14:27 ## IKEv2 DBG : Recv IKEv2_CREATE_CHILD_SA[36] Request msgid 2 from 3x.xx.x5.1x, Peer is IKEv2 Initiator
2025-01-30 19:14:27 ## IKEv2 DBG : Process Packet : Receive IKEv2_CREATE_CHILD_SA request but can't find corresponding IKE SA for iCookie = 736cREDACTED496 rCookie = 1fdbREDACTEDf32a from 3x.xx.x5.1x
I know the timestamps don't quite match there, this is just because the web syslog on the Dial-In router had overwritten the entries by the time I copied the logs.
I have had success rebooting one or both ends of the tunnel, which sorts the problem out for a time, but then the same thing occurs.
Apologies if that is not quite clear, can provide any more details if required. Would really appreciate any suggestions.
Last edit: 30 Jan 2025 19:24 by m_d. Reason: Clarified title. Added additional info.
Please Log in or Create an account to join the conversation.
- m_d
- Topic Author
- Away
- New Member
Less
More
- Posts: 9
- Thank yous received: 0
31 Jan 2025 17:27 #104523
by m_d
Replied by m_d on topic Load Balance IPSec Tunnels not connecting / dropping.
Should also mention: If I disable the trunk and 2nd VPN tunnel on the Dial-Out router, the remaining tunnel is stable, rather than dropping frequently.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek