Solved

Cisco ASA IPSEC L2L Tunnel EqualLogic Replication Problems

Posted on 2010-11-22
4
2,103 Views
Last Modified: 2012-05-10
As part of as VMWare SRM manager setup, I have the following setup at two data centers:

<Data Center A>
EqualLogic SAN Primary Array
        |
Pair of Dell 5424 switches
        |
        |      <vlan for storage network>
        |
Dell 6224 Layer 3 switch (default gateway for all network traffic)
        |
        |
Cisco ASA 5510
        |

IPSEC L2L tunnel (passes all vlans)

        |
Cisco ASA 5510
        |
        |
Dell 6224 Layer 3 Switch (default gateway for all network traffic)
       |
       |      <vlan for storage network>
       |
Pair of Dell 5424 switches
       |
EqualLogic SAN Backup Array
<Data Center B>


I have setup EqualLogic replication between both of the SAN arrays across the L2L tunnel.  Data is replicated, but replication is very sporadic (will work for a few minutes, stop working, continue working again, and so on, until it eventually times out with a “partner down” status).  According to the EqualLogic logs, connectivity is lost between the partner arrays when replication stops.

I’ve tested the obvious and am positive there is no loss of basic connectivity between the sites.  With the aid of EqualLogic support, I tested to ensure that each interface on each controller on both sides could pass a packet back and forth with no loss.  We also confirmed there is adequate bandwidth and the connection is very low latency (there is about 40 meg of throughput).  Additionally, we confirmed it is not a space issue.

Finally, we issued a command on the source EqualLogic to use standard size frames for replication (the command was support repl-use-jumbos no).

My gut tells me the ASA is messing with the packets.  So, going down that route, I did the following:

1.      Disabled all packet inspection
2.      clear-df bit on the tunnel
3.      messed with different sysopt connection tpcmss settings

So far nothing has helped.  

My other thought is that the 6224 is messing with the traffic as it is being passed through.  The vlan for the storage network is not tagged (EqualLogic does not support a tagging).  The pair of 5424’s are connected to a port on the 6224 that is a member of the storage vlan.  That vlan forwards its traffic along the switch’s default route to the ASA so it can get across the L2L tunnel.  I haven’t messed with any of the port settings on the 6224 for the storage vlan, or on the port from the 5424’s that connects them to the 6224.  Only the ports that are connected to the VMWare hosts and SAN are “optimized” for iSCSI (flow control enabled, spanning-tree disabled, etc).  

Does anyone have any thoughts or a similar setup they can share with me?

0
Comment
Question by:entegration
  • 2
4 Comments
 
LVL 42

Expert Comment

by:kevinhsieh
ID: 34219314
Do you have any problems running FTP, SCP, CIFS or NFS data transfers across the VPN? You should probably contact Cisco. I don't normally run my EqualLogic replicatioin over my ASA IPSec VPN, but I don't remember having any issues with it, and I haven't made any changes to the EqualLogic side, and I don't think that I did anything special to the ASA.

You should use ASDM to look at the ASA statistics and logs while replicating traffic to see if anything pops up there, but I still go back to you should contact Cisco.
0
 
LVL 1

Expert Comment

by:leebaskin
ID: 34234026
I am having the same issue, just with a different firewall (Sonicwall)

I was told that the problem was with NAT. I dont know exactly how to fix it as I am still working on it but I was passed a document that explains what the problem is.

See attached Txt doc. EqualLogicReplication.txt EqualLogicReplication.txt
0
 

Accepted Solution

by:
entegration earned 0 total points
ID: 34262540
I figured it out.  The 6224 was interfering with the replication traffic.  I took a free interface on my firewall and hooked right into the iSCSI backend switches and routed the traffic over the tunnel that way.  It replicates now no problem.  
0
 

Author Closing Comment

by:entegration
ID: 34289980
I figured it out myself, just providing the answer for others.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ESXi 5.5 SSH service keeps stopping 6 57
Dropbox for Free 5 33
S2D for SMB or vSAN 1 23
Converting a certificate into a PEM 2 19
In this article we will learn how to backup a VMware farm using Nakivo Backup & Replication. In this tutorial we will install the software on a Windows 2012 R2 Server.
Each year, investment in cloud platforms grows more than 20% (https://www.immun.io/hubfs/Immunio_2016/Content/Marketing/Cloud-Security-Report-2016.pdf?submissionGuid=a8d80a00-6fee-4b85-81db-a4e28f681762) as an increasing number of companies begin to…
Teach the user how to install and configure the vCenter Orchestrator virtual appliance Open vSphere Web Client: Deploy vCenter Orchestrator virtual appliance OVA file: Verify vCenter Orchestrator virtual appliance boots successfully: Connect to the …
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question