Solved

Issue with dropped packets and request time outs to remote sites

Posted on 2011-03-21
10
646 Views
Last Modified: 2012-05-11
I am having an ongoing issue with my remote site losing connectivity to my cooprate office.  The sites are connected via a VPN tunnel using 2 Edgemarc routers.  I have been trying to drill down on the cause of the issue but have been unsuccesful so far.

I decided to give Wireshark a try and see what it said about my issue.  During a file copy/ping -t from Site A to Site B I noticed a bunch of ICMP messages saying ICMP Redirect (Redirect for host).  The redirect is occuring from Source (192.168.10.1) and destination (192.168.10.3).  I find it odd that there is an ICMP Redirect occurding within the same subnet, not sure if this is what I should be seeing or not.

There are also a bunch of Write AndX request yellow and red/black bars with TCP out of order errors.  I'm new to viewing this data, so if there is anything I should be looking for in particular to futher troubleshoot this, any guidance is appreciated!
0
Comment
Question by:jmchristy
  • 4
  • 4
  • 2
10 Comments
 
LVL 24

Expert Comment

by:rfc1180
ID: 35184508
>Source (192.168.10.1) and destination (192.168.10.3)
So what are these devices, are you running some type of IGP in the network or any static routes between these 2 devices.

You might need to added no ip redirect on the interfaces of the hosts default gateway.

Billy
0
 

Author Comment

by:jmchristy
ID: 35184524
192.168.10.1 is the Edgemarc Router
192.168.10.3 is a server which just has a 2008 R2 base install done, nothing else

The Edgemarc router is the default gateway for all the computers and servers in the remote location.  No IGP is running that i'm aware of.  I do see this IGMP direct quite a bit in the wireshark logs during my file transfer/ping -t testing.
0
 
LVL 24

Expert Comment

by:rfc1180
ID: 35185034
on the edgemarc router if a Cisco, add the line:

no ip redirect

on the interface that is directly connected on the LAN.

Billy
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 5

Expert Comment

by:ravisimpi
ID: 35187780
WHen you say you have connectivity problem, what actually is it?

Your total tunnel is coming down? Any applications stops working, or any file download is un success-ful?

Is it possible for you to share the wire shark capture file
0
 

Author Comment

by:jmchristy
ID: 35188084
My tunnel isn't going down, the Edgemarc never says the tunnel isn't established anymore.  

It happens when a file transfer is occuring, a user from Site B (remote site) tries to open a file from Site A.  The file download takes awhile, and if I begin pinging the file server at Site A from the user's PC at Site B  I see a bunch of request time outs while the file is being downloaded.
0
 
LVL 5

Expert Comment

by:ravisimpi
ID: 35195863
I understand that you have two routers connected to the LAN segment and the User's PC at Site B is being configured with a gateway of a router who don't have a direct route to Site-A.

When the packets hit this router (suppose on interface-1 connected to LAN segment) it checks it's routing table and finds that the exit interface for that packet is same on which it has received it.

 You can try changing the default gateway configured on on user's PC at site B and point it to a router which is having a direct route (not pointing to the LAN segment) to site-A.

peace and health,
Ravindra
0
 
LVL 5

Expert Comment

by:ravisimpi
ID: 35195864
Also, is it possible for you to share the capture file?
0
 

Author Comment

by:jmchristy
ID: 35197584
So maybe try changing the gateway to say a layer 3 switch and have that handle the routing?

The Edgemarc at Site B is setup to do the routing now, the VPN tunnel I'm assuming is handling the routing of the traffic to Site A.  If it's within the same subnet, I would think it wouldn't even need to the gateway.

Do I need to add a route at Site B's Edgemarc for Site A? Even though it has a VPN tunnel established?  Or will it check that VPN tunnel first to know where to send the packets for the different subnet?
0
 

Author Comment

by:jmchristy
ID: 35197586
I can put together another wireshark file
0
 
LVL 5

Accepted Solution

by:
ravisimpi earned 500 total points
ID: 35204483
You must be running a routing protocol on the routers. Check the routing on both the routers (on site-A and also on site-B) and verify that the destination is pointing to proper interface (in your case "tunnel interface") If you have multiple route for same destination, then I would recommend changing the cost of the route so that the packet leave the tunnel interface.

peace and health
Ravindra
0

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Setup another VLAN on Fortigate 3 30
Cisco  3750E switches 1 28
Cisco WRVS4400N 11 37
Swapping port on a  Cisco 5510 firewall 1 23
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question