Link to home
Start Free TrialLog in
Avatar of Denny Farrell
Denny FarrellFlag for United States of America

asked on

"this QM message ID is lower" Sonicwall VPN tunnel error

I cannot seem to find any articles on the log error "this QM message ID is lower". This error is for the site-to-site VPN tunnel between Sonicwalls NSA240 and TZ200.

The site to site VPN tunnel keeps going up and down every few minutes.

Any help would be greatly appreciated,
ASKER CERTIFIED SOLUTION
Avatar of Blue Street Tech
Blue Street Tech
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I'd agree with diverseit... it's probably the policy lifetime which is causing this.
learn_it,

Any update on this?
Avatar of Denny Farrell

ASKER

This tunnel has been doing very well for over a year. It just started throwing the message and renegotiate non-stop a few days ago. In fact, it did seem to self-heal yesterday morning. No more messages of any kind - possibly an ISP issue?

Policy lifetime is set to 28800 on both ends at this time.
Once you have gone through everything in my comment http:#a39494629. Let me know if the issue still persists.

Then you can try sizing the MTU by following these instructions: https://www.experts-exchange.com/A_12615.html
Yeah if it was running fine with no config changes, then just started to fail, I'd look at the ISP side of things.

I've had a situation where the ISP decided to route my traffic through a different access switch which had a dodgy ACL applied.  This broke my IPSec traffic.  I've seen all kinds of issues with ISPs causing problems.  They recitfy it soon enough once you complain to them, but they'll never admit it.
Yeah, I know...they are so shady!
Any issue on this?
diverseit, craigbeck

Thank you for your input in this thread. We have been doing well for a while now. The issue went away as unexpectedly as it appeared.

I have checked settings according to diverseit's comments. These are the directions we used during the initial tunnel setup. Everything checks out.

I consider this question resolved at this time since there is no issue and logs of it happening anymore.
Glad I could help...thanks for the points!