Watchguard XTM330 firewall BOVPN problem

I've been having some problems with my office BOVPN lately, randomly the bridge between our two offices breaks. We have two identical XTM330 firewalls on both locations and both have the same configuration, done using this guide:

http://www.watchguard.com/help/docs/webui/11/en-us/content/en-us/bovpn/manual/manual_bovpn_fireware-xtm_fireware-xtm_web.html

But sometimes randomly the tunel stops working and we can't access the other office's network. Usually resetting the firewalls temporaly fixes the issue.

I got the following debug messages off both firewalls logs:

Office A firewall

Process=iked  msg=(officeAExternalIP<->officeBExternalIP)MWAN-Failback notify ikePcy=0x1078b638(officeBTunel), p1said=0xc645b540 UP

Process=iked  msg=(officeAExternalIP<->officeBExternalIP)MWAN-Failback failed to find the ikePcyGrp by ikePcy - name=officeBTunel

Office B firewall

Process=iked  msg=(officeBExternalIP<->officeAExternalIP)MWAN-Failback notify ikePcy=0x1078b638(officeATunel), p1said=0xc645b540 UP

Process=iked  msg=(officeBExternalIP<->officeAExternalIP)MWAN-Failback failed to find the ikePcyGrp by ikePcy - name=officeATunel

Does anyone know what could be causing this?
ScreenFoxAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

dpk_walCommented:
Looking at the logs it looks like that there was disruption in internet service...WG tried to fallback to backup internet [which I guess is not configured in your network] and did not succeed.

Can you make sure that the internet indeed remains up all the time.

Also, please make sure that you have configured IKE keep-alive...though not directly relevant here but can help.
As per link you posted:
Select NAT Traversal, IKE Keep-alive, or Dead Peer Detection (RFC3706). Make sure you select the same values you chose in the BOVPN Tunnel Settings.

Please check and update.

Thank you.
0
ScreenFoxAuthor Commented:
I checked and right now the firewalls are using dead peer detection, before we were using only IKE keep-alive but the problem started happening so following the recommendation of the guide on that link I changed IKE keep-alive for Dead peer detection.

But the problem it's still there. I checked the Internet connections and no user has reported any problem with the internet.

Thanks for your reply
0
dpk_walCommented:
You can configure both DPD and IKE keep-alive at the same time.
What I want to understand is that when VPN tunnel goes down; at that time, does that happen because of internet going down?
Also, is multi WAN configured at the sites.

Thank you.
0
What were the top attacks of Q1 2018?

The Threat Lab team analyzes data from WatchGuard’s Firebox Feed, internal and partner threat intelligence, and a research honeynet, to provide insightful analysis about the top threats on the Internet. Check out our Q1 2018 report for smart, practical security advice today!

ScreenFoxAuthor Commented:
In Office A there is a multi WAN configured, and no, when it has happened the connection to the internet was fine.
0
dpk_walCommented:
Are there any more logs which might explain the issue.
Its tough to say what is exactly happening with limited information.
0
BrianCommented:
Have you tried setting the VPN tunnels to use Main Mode with fall back to Aggressive Mode? Aggressive Mode is not as secure, but if the tunnel connection or re-keying messages get garbled or drop a packet, Aggressive Mode will fight through it.

Double check every single firewall setting between the two. Especially time out settings.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.