Avatar of ScreenFox
ScreenFoxFlag for Spain asked on

Watchguard XTM330 firewall BOVPN problem

I've been having some problems with my office BOVPN lately, randomly the bridge between our two offices breaks. We have two identical XTM330 firewalls on both locations and both have the same configuration, done using this guide:

http://www.watchguard.com/help/docs/webui/11/en-us/content/en-us/bovpn/manual/manual_bovpn_fireware-xtm_fireware-xtm_web.html

But sometimes randomly the tunel stops working and we can't access the other office's network. Usually resetting the firewalls temporaly fixes the issue.

I got the following debug messages off both firewalls logs:

Office A firewall

Process=iked  msg=(officeAExternalIP<->officeBExternalIP)MWAN-Failback notify ikePcy=0x1078b638(officeBTunel), p1said=0xc645b540 UP

Process=iked  msg=(officeAExternalIP<->officeBExternalIP)MWAN-Failback failed to find the ikePcyGrp by ikePcy - name=officeBTunel

Office B firewall

Process=iked  msg=(officeBExternalIP<->officeAExternalIP)MWAN-Failback notify ikePcy=0x1078b638(officeATunel), p1said=0xc645b540 UP

Process=iked  msg=(officeBExternalIP<->officeAExternalIP)MWAN-Failback failed to find the ikePcyGrp by ikePcy - name=officeATunel

Does anyone know what could be causing this?
Hardware FirewallsNetworking Hardware-Other

Avatar of undefined
Last Comment
Brian

8/22/2022 - Mon
dpk_wal

Looking at the logs it looks like that there was disruption in internet service...WG tried to fallback to backup internet [which I guess is not configured in your network] and did not succeed.

Can you make sure that the internet indeed remains up all the time.

Also, please make sure that you have configured IKE keep-alive...though not directly relevant here but can help.
As per link you posted:
Select NAT Traversal, IKE Keep-alive, or Dead Peer Detection (RFC3706). Make sure you select the same values you chose in the BOVPN Tunnel Settings.

Please check and update.

Thank you.
ASKER
ScreenFox

I checked and right now the firewalls are using dead peer detection, before we were using only IKE keep-alive but the problem started happening so following the recommendation of the guide on that link I changed IKE keep-alive for Dead peer detection.

But the problem it's still there. I checked the Internet connections and no user has reported any problem with the internet.

Thanks for your reply
SOLUTION
dpk_wal

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER
ScreenFox

In Office A there is a multi WAN configured, and no, when it has happened the connection to the internet was fine.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
dpk_wal

Are there any more logs which might explain the issue.
Its tough to say what is exactly happening with limited information.
ASKER CERTIFIED SOLUTION
Log in to continue reading
Log In
Sign up - Free for 7 days
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.