Solved

Netgear FVS 318 Dropping VPN Connection

Posted on 2006-11-08
5
1,886 Views
Last Modified: 2012-06-27
Hello Experts,

We have several VPN tunnels that connect Windows 2003 Servers to an AIX box. At the Windows servers we are using the Netgear FVS 318 (version 2.4 - 3.1) and on the AIX side we connect to a BSD box that functions as a VPN router. These tunnels are IPSec based with AES 256 encryption (Healthcare Information) and transfer data back and forth through FTP services. Some of the connections are getting Dropped at night when the system is Idle. The Netgears show the connection as Established but the AIX is unable to FTP into it, we have to go in and DROP then re-establish the connection on the Netgears, then all is good again.

We have 12 of these running and its getting tiresome to have to do this every morning. Before we throw the Netgears out and drop the big bucks on Cisco does anyone have any suggestions? I have of course set the IKE Keep Alive and the Ping IP address to the AIX Server.

Any help will be greatly appreciated,

Jack W
0
Comment
Question by:JackW9653
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 77

Accepted Solution

by:
Rob Williams earned 500 total points
ID: 17901130
A few things you might want to check:
-Are these PPPoE connections by any chance?  If so, in the router wan configuration, make sure The "idle Time out" is set to 0  this will disable time outs.
-Also on the Net gears, under the VPN policy, there is a keep alive option where you can provide an IP, preferably at the remote VPN site, to ping on a regular basis to maintain the connection.
-On any servers or PC's check the Power Management section of the network adapter. Most newer cards have this option and Windows seems to enable "allow this computer to turn off this device to save power" by default.
0
 

Author Comment

by:JackW9653
ID: 17901365
Hello Rob,

Thanks for the reply. I will answer your questions in order:
- I don't think that any of the connections are over DSL which is where I have seen the PPPoE issue, but I will verify that. Also I could not find a WAN Configuration area of the router setup.
- As I mentioned in my original question I have checked the IKE Keep Alive and used the address of the remote AIX box
- I hadn't thought of the NIC going to sleep on me - I will check that out.
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17902565
-quite right if not a DSL connection it will not be PPPoE.
The WAN section on an FVS318 is actually called "Basic Settings". If you have PPPoE connection the First item "Does your Internet Connection require a logon" will be marked Yes.
-sorry I somehow missed your comment about having enabled the keep alive. Having that enabled should make the PPPoE  alive feature, if you had PPPoE, and power management, not an issue anyway, as it would maintain an active connection. Sorry no other ideas.

I often set up a small utility called IPMonitor when having connection issues. It is basically a ping tool that can be set to monitor multiple IP's by pinging them every minute and then create an error log when the connection is dropped. I set it up to monitor a local machine, the router's LAN IP, the ISP's modem (your ISP's gateway address), and Internet IP such as a DNS server, and a device at the other end of the VPN tunnel. Though this won't solve anything, it does help to show where the connection is dropped, how often and for how long.
http://ipmonitor.tsarfin.com/
0
 

Author Comment

by:JackW9653
ID: 17909295
The NIC card was the key! Thanks Rob - I wonder who at Dell decided that they needed to PowerSave on a Server? The total resolution was to increase the SA Life time to 16 hours and turn off the powersave on the NIC.

Thanks Again,

Jack
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17909399
>>"wonder who at Dell decided that they needed to PowerSave on a Server"
I think that is actually Microsoft. Can't be live it is even an option, but it has been common lately.

Thanks Jack
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
l2tp tunnel from pc to router 14 116
Site-To-site VPN Natting inbound traffic? 9 112
Juniper VPN for Mac and windows OS 5 70
Bizarre IP Address / Port Blocking Windows 7 13 81
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question