Question

Watchguard SOHO firewall in office drop connection several times a day, what's wrong

Asked by: peteryau

The branch office was equipped with SOHO firewall  behind the ISP router for few years and working fine and had never change the firewall configuration.  In these two weeks we found the internet connection disconnected several times a day and the ISP router and modem has been replaced and still got the problem.  I found out this is not the ISP router nor modem problem because I can ping the ISP router from outside when disconnection occured.

All internal PCs are installed with Symantec anti virus corporation v10.1 or endpoint protection v11.
I touch the surface of firewall and found no heating problem.
The firewall drop connection in a very short interval and all logs are clear when it can be connected again.  I also found the firewall did not reboot because the VPN connection resume very fast . (if for rebooting, it will takes over 3 minutes to establish the connection).  I notice the connection suddenly dropped because our terminal server session through VPN suddenly dropped off. But it can be resumed after reconnect  using the terminal client again.


Anyone could help me on troubleshooting?  

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-12-21 at 03:25:40ID23037896
Tags

firewall

,

soho

,

connection

,

drop

,

watchguard

Topics

Anti-Virus

,

Networking Hardware Firewalls

,

Networking Security Vulnerabilities

Participating Experts
1
Points
500
Comments
24

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Watchguard SOHO VPN -> Checkpoint FW1
    Hi, I have a IPSEC VPN setup between location 1 and 2. - Location 2 is a remote office using ADSL as an internet connection and a SOHO watchguard (latest firmware) for security and VPN. - Location 1 is the main office running Checkpoint FW-1 Once the tunnel is active ever...
  2. SOHO VPN Router
    Can anyone briefly comment / or refer some websites that review the SOHO VPN router manufacturer, e.g. Linksys, D-Link, NetGear, etc, in regard to VPN router's performance, stability, quality etc. Also, would it be appropriate to utilize product from Linksys or D-Link in sma...
  3. Watchguard Additional Network cannot reach VPN networks
    I have a watchguard X700 withsetup to use 172.16.0.0/24 on the trusted interface. I have several VPN tunnels setup to remote networks on the Watchguard, ex. 192.168.1.0/24. I have the ANY to ANY rule for these 2 networks and evertyhing works fine. On the Watchguard I added an...
  4. VPN SOHO 6
    Hello, Ok so I'm working with firebox soho 6, dynamic external ip from ISP, and I want to be able to connect to the location by VPN ... how?
  5. Watchguard Firebox SOHO 6 & Remote Desktop - cannot…
    I have recently installed a Watchguard Firebox SOHO 6 into my network - and since that i cannot use RDC(remote desktop connection). My Network diagram: SERVER 1&2 and Home PC -> SOHO 6 -> Netgear Wireless router -> Internet I have forwarded all RDC ports(3389 - ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: dpk_walPosted on 2007-12-21 at 22:32:36ID: 20517905

What version of SOHO software you have, if you have SOHO6 make sure you have 6.4 (latest available) installed as it has 7000 NAT ports.

Sometimes if any of the machines on the internal network is affected by malware it can cause junk traffic on the network and traverse to the internet, consuming all the available NAT ports in the process. Checking machines that they are clean of malware would help.

I would like to know when the connection drops, does reconnecting brings the connection up or is there something more to be done; also, does the users on the internal loose internet connectivity when you loose connection.

Please check and update.

Than you.

 

by: peteryauPosted on 2007-12-22 at 07:14:47ID: 20518754

thanks for yr help. dpk. When the connection drops, the reconnecting is automatic within a minute without any physical restart of the firewall.  The internet use may not sense the disconnection when only on the internet but the VPN users with remote desktop connection to the server in remote site will sudden dropped off.   They need to reconnect the remote desktop connection again.

 

by: peteryauPosted on 2007-12-22 at 18:20:56ID: 20520316

here is the network statistics log after the disconnection and auto reconnect:  The time is random, sometimes it can be up for few hours.
IP:      Up for 38 minutes 7 seconds
      Network Buffers Allocated/Total (0/10) Memory Total/Largest Block (667760/559312)
      Sockets Allocated/Total (14/40) NAT Ports Avail (997)RAM Disk (47104)
      Tx: packets (25015)
      Rx: packets (32363) hdr Err(102) delivered (903)
      reassemble (340)
      forward (23985)
      reassemble OK (169)
      fragments fail (6)

 

by: dpk_walPosted on 2007-12-22 at 20:04:43ID: 20520531

So as I understand the connection to the ISP is dropping; did your ISP make any new changes? Also, what about the firmware, is it running latest firmware.

The problem I was saying it appears is not applicable to your situation as its not WG which runs out of NAT ports; but the connection to the ISP is dropping. Situation of inactivity timers kicking in is also ruled out because you have an active VPN session.

Is your connection PPPoE; can you at least capture the IP information as in is it that when the IP address on SOHO changes (if it is dynamic) the connection drops.
UP information which you listed; is it the device uptime, if yes, then it means that your box itself is rebooting.

I would need more information on what actually is happening.

Thank you.

 

by: peteryauPosted on 2007-12-23 at 05:47:54ID: 20521286

The ISP does change the router and the modem as we suspected at first that this is due to their problem. However, we can still ping the ISP router from external when the internal connection to internet is suddenly dropped.  
The Watchguard SOHO seem to link down and then immediately up on the internal ethenet port rather than reboot because it did not takes long to resume connection.  (Usually reboot takes at least 2-3 minutes to resume connection).

 

by: peteryauPosted on 2007-12-23 at 22:18:11ID: 20523716

Today I put a syslog server to monitor the log and found that there is error message of "memory pool exhausted" before the firewal lauto-reboot.
 What should I do next?

 

by: dpk_walPosted on 2007-12-24 at 03:12:44ID: 20524237

memory pool exhausted: indicates the problem I was earlier thinking - NAT pool exhaustion

Your device is running out of NAT ports. Sorry, but I don't remember exactly but there is a hidden page in SOHO where you can see the machines and the ports utilized [the reason I thought it was not the case was because in the comment ID: 20520316; number of NAT ports was 997], I think the hidden page is:
http://internal-ip-address/debug.htm
or
http://internal-ip-address/debug.html

[Request you to please confirm which is correct]

Opening this page would give you an option to see the machine IP address which are sending traffic out. With this you would be able to corner one machine which is responsible for eating all the NAT ports and is possibly affected by malware. Remove the said machine from network and then check; the problem should cease to occur.

You can clean the machine and then put it back to network and still the things should be good.

Please check and update.

Thank you.

 

by: peteryauPosted on 2007-12-24 at 06:17:34ID: 20524665

 

by: dpk_walPosted on 2007-12-24 at 06:45:50ID: 20524776

Thank you; were you able to gather some information regarding the rouge machine IP.

 

by: peteryauPosted on 2007-12-24 at 08:14:38ID: 20525087

Will check it after the holiday. thanks

 

by: peteryauPosted on 2007-12-27 at 00:25:26ID: 20532900

I found one of the workstation IP has over 24 sessions occupied (through the debug.htm) with each session having  timeout over 5000.
Is it normal for that?  

Thanks

 

by: dpk_walPosted on 2007-12-27 at 01:08:20ID: 20532993

Just 24 would not be too much of botheration; I think may be due to less traffic at this time you are not reaching the situation (NAT pool exhaustion); or may be the rogue machine is switched off; when the traffic is full you would see hundreds of connections initiated from the rogue machine. I think 5000 seconds is the default timeout for a session (though I am not 100% sure).

If you are running firmware version 6.1 or lower you would have 1000 NAT ports; if you are running 6.4 then you would have 7000 NAT ports.

So, the box with 6.4 would reach the situation later when compared to older firmware.

Thank you.

 

by: peteryauPosted on 2007-12-27 at 03:00:32ID: 20533320

the firmware is only 5.x because this is an old SOHO firewall.  Suddenly I found there is another PC with  same computer name (not IP address) on the same network.   Will it cause the trouble on above issue?

 

by: dpk_walPosted on 2007-12-27 at 03:30:59ID: 20533402

Same computer name would not cause the issue you are facing; I think you have SOHO5 [not SOHO6 as I was earlier thinking]; SOHO5 or SOHO as they are called would have only 1000 as max NAT ports. Same name can cause problems where NetBIOS/WINS is used; most networks run DNS; it would be a good idea to correct it though.

Please check the NAT port status when the problem occurs and that would give you good deal of information about the machines and their outbound connections.

It would be a good idea to keep two pages open for SOHO configuration; one showing the summary you posted earlier where you can see NAT ports and the other page showing hidden page info.

Thank you.

 

by: peteryauPosted on 2007-12-27 at 18:35:58ID: 20539222

strange , this is the network statistics few seconds before the firewall reboot.  Seems no exhausting on the firewall.  And the debug page on NAT ports show only few connections.  The firewall only up for 12 mins and reboot.
-----
Up for 12 minutes 11 seconds
      Network Buffers Allocated/Total (2/10) Memory Total/Largest Block (718288/663968)
      Sockets Allocated/Total (11/40) NAT Ports Avail (996)RAM Disk (47104)
      Tx: packets (29463)
      Rx: packets (42862) hdr Err(89) delivered (1187)
      reassemble (1246)
      forward (28369)
      reassemble OK (621)
      fragments fail (9)

 

by: dpk_walPosted on 2007-12-27 at 21:50:38ID: 20539931

If you have the firmware for the unit, try loading it again; or if possible, reset the unit to factory defaults and reconfigure it; the problem might be related to firmware/hardware. Did you have any storms or power surges after which the problem started; or all of a sudden problem started happening.

Before you reset the unit, it would be good to keep a backup of current configuration.

For creating backup of WG config, make sure ftp access to SOHO is enabled [From configuration select Firewall > Firewall Options; clear the check box adjacent to Do not allow FTP access to the Edge from the Trusted Network; click Submit to save your changes], then

      1.       Open command prompt window.
      2.       ftp to SOHO_internal_IP.
      3.       Enter the admin user name and password.
      4.       Switch to binary transfer mode by typing bin.
      5.       Do get wg.cfg
      6.       Type quit to close the FTP connection.

To restore a Backup Configuration File
In step 5 above do put wg.cfg instead of get. Please note you would need to restart your SOHO to force the changes to effect.

You can look at the following article from WG detailing the above procedure [please note you would need to have a valid username/password for WG website]:
https://www.watchguard.com/support/faqs/edge/edge86/edge_gen_backup-config.htm

Thank you.

 

by: peteryauPosted on 2007-12-27 at 22:32:43ID: 20540077

However, there is no problem after office closed and no one using the computer.  Malware is the first suspect but we have already using symantec endpoint to scan and no results.

 

by: dpk_walPosted on 2007-12-27 at 23:04:10ID: 20540156

I think it has to do with traffic; as I said may be firmware on the unit has got something incorreclty written to it; so causing the problem; resettings the unit to factory defaults and reconfiguring should get rid of that.

The other things possible is that your network usage exceeds the capabilities of SOHO and that's the reason the problem is not seen in off hours. Upgrading the box would be a good option in such a case.

Thank you.

 

by: peteryauPosted on 2007-12-27 at 23:10:36ID: 20540173

We alreay lost the manual,  after the factory default reset, any default login and  password for the soho and what is the default IP address of it?

thanks

 

by: dpk_walPosted on 2007-12-27 at 23:29:40ID: 20540227

Default IP would be 192.168.111.1; username/password should not be there; you need to go the SOHO configuration page [system security] and configure yourself for username/password.

I would strongly recommend to create backup of the current configuration.

Reset procedure:
1. Disconnect the power on the SOHO.
2. Use a standard Ethernet patch cable to connect the WAN and 1 ports together.
3. Connect power to the SOHO.
4. The SOHO will turn on. Wait 90 seconds for the reset process to complete.
5. The MODE and ON lights will eventually flash simultaneously, indicating the process is complete
6. Disconnect the power from the SOHO.
7. Disconnect the Ethernet cable from the 1 and WAN ports.

Reconnect the power to the SOHO. The reset procedure is now complete.

Please note all your settings including VPN settings would be wiped off; please remember all the settings so you can configure them back.

Thank you.

 

by: peteryauPosted on 2007-12-28 at 01:45:03ID: 20540655

Before I reload the firmware, I want to  provide more info from the syslog :

16:11:24  MONIITOR: ipsec0: packet (5da2) faled with authentication failed, SPI=1350435840, src=125.215.184.201, dest=x.x.x.x, sa.saddr=x.x.x.x, sa.daddr=x.x.x.x
16:12:15  IP:  entry duplicated 1 times @2007-12-28-16:20:36
16:12:29  MONIITOR: ipsec0: packet (6b81) faled with authentication failed, SPI=1350435840, src=125.215.184.201, dest=x.x.x.x, sa.saddr=x.x.x.x, sa.daddr=x.x.x.x
16:12:53  MONITOR: System memory pool exhausted  @2007-12-28-16:11:38
16:12:55  MONITOR:  somebody wanted a reboot @2007-12-28-16:11:40

any hint on above?  Thanks

 

by: dpk_walPosted on 2007-12-28 at 03:14:42ID: 20540972

>> 16:12:53  MONITOR: System memory pool exhausted  @2007-12-28-16:11:38

The SOHO is running out of memory, the memory required by the processes is more than what device can handle.
SOHO5 has been EOL for long, I think 2005 April (not sure), so even WG would not have public documents on upgrading physical memory (I am not sure if that is possible).

I think you had earlier also told me about the message; at that time I thought it was NAT pool; but now reading the messages it is clear system itself running out of memory and subsequently getting rebooted.

If you wish you can try resetting the unit and see if that makes any difference; otherwise, your networks would need a new device.

Thank you.

 

by: peteryauPosted on 2008-01-12 at 09:56:29ID: 20644707

I finally replaced the watchgurad soho with another firewall and everything OK now.  It really the old soho firewall cannot handle the traffic - over exhausted.
Thanks

 

by: dpk_walPosted on 2008-01-12 at 19:57:09ID: 20646353

Good to know the problem is resolved.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...