Solved

WatchGuard Firebox IPSec VPN Timeout Issue

Posted on 2008-10-09
8
2,275 Views
Last Modified: 2013-11-16
I think my VPN might be timing out in a strange manner.  The MUVPN remains connected but after some time, I am unable to access anything on the network unless I reconnect the VPN.  Once I reconnect, everything is fine again.  My developers who are constantly sending data through the VPN have not mentioned anything about it.  My supervisor and I use the VPN but the connection is often left idle.  We are the ones who lose the ability to communicate to the network unless we reconnect the VPN.
0
Comment
Question by:mansurw02
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 1

Assisted Solution

by:crumber
crumber earned 250 total points
ID: 22682886
We had a similar problem and had the VPN keep alive set with the other IP address.  This eliminated the VPN from going down when left idle for too long.

Hope that helps.
0
 

Author Comment

by:mansurw02
ID: 22683048
I am not sure I understand what you mean.  How would I configure a keep alive with an IP address?  I am using WSM 10.2 and MUVPN with IPSec V. 10.  Thanks!
0
 
LVL 1

Expert Comment

by:crumber
ID: 22683614
We are using the X10e-W (Firebox X).
I am not sure how that differs from your version; however if you go to the VPN configuration, select the VPN Keep Alive section and add the local Host IP address of the other point to the Echo Host list.
Hope that helps.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:mansurw02
ID: 22683708
I've got the Firebox X5500e.  I don't see an option like that.  Thanks for helping.
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 250 total points
ID: 22684701
As crumber said; you are reaching the timeout value and as a result the VPN gets terminated and you need to reconnect; to overcome this you can create a batch file which would send ICMP packets to the remote network every x seconds; this way the connection would not time out.

You can create a batch file as below [remember to execute it once you get connected to VPN]:
ping <remote-machine-ip-adress> -n 1
sleep 60

Here, sleep is an external utility which you can download from the internet [please evaluate it for security based on your company's policy].

Otherwise you can simply configure a ping with -t option as below:
ping <remote-machine-ip> -t

Thank you.
0
 

Author Closing Comment

by:mansurw02
ID: 31504847
It's working fine now.  Thanks for the help!
0
 

Expert Comment

by:BERTLEEMAN
ID: 23393496
The problem is that the firewall is sending a keep alive packet to the muvpn client on udp port 4500. When there's no exception in your windows firewall (udp 4500) then you are disconnected after 3 minutes. this is only applicable with the muvpn software ver 10.00.... and newer
0
 

Expert Comment

by:visionmn2
ID: 38203748
First create a folder in root of C: named Ping (or wherever, whatever)

Then created a batch file png.bat in Notepad or your favorite text editor

Place the following line in the batch file and save where 10.0.0.10 is the IP of a remote resource such as a server:

ping 10.0.0.10 –n 1

Save the batch file

Then create a 2nd file in that same folder called png.vbs (from notepad or text editor). Just copy and pasted the following and change the file path if you are not following this example.

Set WshShell = CreateObject("WScript.Shell")
WshShell.Run chr(34) & "C:\Ping\png.bat" & Chr(34), 0
Set WshShell = Nothing

Save the png file

Set-up a scheduled task in Windows Task Scheduler to run every day starting at 12:01am – and will repeat every 3 minutes or whatever time before it times out until 11:59pm.
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Macbook Sierra OS OpenVPN issue 13 150
How to setup 3 isps on a redundant mode? 3 36
Palo Alto site-to-site vpn monitoring 5 46
pptp through Cisco ASA5505 V7 5 30
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question