Solved

Troubleshooting a Watchguard to Watchguard VPN

Posted on 2014-11-11
6
284 Views
Last Modified: 2014-11-26
I don't know much about watchguard firewalls.  A previous person set up a branch office VPN between 2 watchguard firewalls (X10e? and XTM2)

It has been working fine for months / years.  Recently, the VPN is broken (I can't ping across it).

If i go into the X10e and reboot it, the VPN is restored.  All other functions were working fine.  The box is several years old and there's no support with Watchguard.

on the x10e, if I go into status, vpn statistics, I see the VPN connection, it has a fair amount of data in all the categories.  

If I highlight the branch office VPN connection (the only one listed), then click rekey selected BOVPN, 1 time I got the message that the VPN doesn't exist... but now it just increments the rekey counter with no error. and no ability to ping / access machines across the VPN

Clicking on the debug button on that page gets the attached file - stuff that I don't understand.  (I changed the remote public IP to a.b.c.d for confidentiality)

A reboot of the x10e gets everything working.  But I rebooted the box a few days ago (it works for a few days then stops, in contrast to previously working for months / years with no problems)

I am used to lynksys type routers.  this is more complicated that I am used to (and more than what's really needed for a small business?)?

I don't see a simple page that says VPN is up or down : (

Any advice?
0
Comment
  • 3
  • 3
6 Comments
 

Author Comment

by:BeGentleWithMe-INeedHelp
Comment Utility
I rebooted and vpn is working.

I compared the debug pages before and after. I did a screen capture of the first few lines.  with broken vpn, the first entry is Next payload ISA_HASH and after reboot that first entry is next payload ISA-SA.

And similar differences down the pages...

any help would be appreciated!
compare-before-and-after-reboot.bmp
vpn-debug-after-reboot---VPN-working.txt
vpn-debug-before-reboot---VPN-not-workin
0
 
LVL 27

Accepted Solution

by:
Steve earned 500 total points
Comment Utility
is there anything we could link up with when it started being unstable? update to XTM2, internet line change etc?

the logs suggest the x10e may be using slightly different settings to the XTM2 which would possibly explain why it may fail after a while, but it would suggest its been unstable in the long term. how recently has it started dropping the vpn?

does either site have internet issues in general?
0
 

Author Comment

by:BeGentleWithMe-INeedHelp
Comment Utility
I compared the pages under the vpn at both ends and the settings seem to be identical (except reversed for local and public IP addresses for each end, as I'd expect).  There was a field for 'pre shared key' that had asterisks.  I cleared that and saved a new password - didn't know what was in the asterisks.  Is that the only password field? with that and the IP of the device on the other end, they handshake and then get into the AES, etc.?

no smoking gun for the cause of the failures.  Internet has been stable as far as I know. I started pinging from a desktop on each end to the watchguard on the other end and also another cmd window pinging google.com.  both are working at both ends now.  I'll check tomorrow for any dropped packets.  and if there was spotty internet, shouldn't the vpn attempt to reconnect? I can get into the machines remotely over the internet, so at that point, the internet is up. so should the VPN?

And other than pinging the other end of the VPN, I can't see in the watchguard web interface how to see that the VPN is up or down. Am I missing something?
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 27

Assisted Solution

by:Steve
Steve earned 500 total points
Comment Utility
hmm. sounds Ok in general then.

does the VPN drop after a 'similar' amount of time on each occasion or is it very random?

If it's similar it would suggest something is expiring or not re-authenticating after a while. It could also mean some kind of buffer/counter may be filling up and failing.
0
 

Author Comment

by:BeGentleWithMe-INeedHelp
Comment Utility
thanks.  I'm looking for someone that knows watchguard specifically that can point me to this page or that / install this software or that, etc. to access logging, etc.
0
 
LVL 27

Assisted Solution

by:Steve
Steve earned 500 total points
Comment Utility
I know Watchguards but not these ones i'm afraid. they're older than i'm used to and you've advised they aren't even upto date :-)

click 'request attention' to see if anyone else can help.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Using Windows 2008 RRAS, I was able to successfully VPN into the network, but I was having problems restricting my test user from accessing certain things on the network.  I used Google in order to try to find out how to stop people from accessing c…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now