Intermittent VPN Pinging Issue - Sonicwall TZ210
Posted on 2013-11-14
This issue is a bit different than other posts I've seen. I recently upgraded the firmware on this TZ 210 to 126.96.36.199-1o. This is a "remote" firewall that is connected via VPN to the "primary" firewall.
The problem is that I lose the ability to ping this remote firewall at approx. 10 pm every night, and also at that time the core monitor utilization begins to climb from negligible to upwards of 30%.
I've determined that when I reboot this TZ 210 in the morning the core monitor utilization drops back to virtually nothing, and the ability to ping the X0 (LAN) interface returns.
This same pattern repeats itself every night at approx. 10 pm after I perform a reboot.
In the TZ 210 logs I find the following entry begins occurring every minute or so at roughly the same time I find the pings stop responding:
Notice - Network Access - ICMP packet dropped due to policy - xxx.xxx.xxx.xxx, 512 X1, <machine sending pings> - xxx.xxx.xxx.xxx, 8, XO - ICMP Echo, Code: 0