Solved

Connection timeouts with mobile vpn users

Posted on 2016-09-25
5
35 Views
Last Modified: 2016-09-26
We just setup a colocation and all connections from our main site to colocation site seem fine.  When remote user connects I start getting timeouts.  Here is the setup.
At main office we have a Watchguard router, at colocation is a Fortigate router.  The gateway and tunnels are setup for site to site between the 2 and it works.
At the main site on the DC, I have sites and services configured accordingly.  The main site subnet is 192.168.0.0/24 and the remote site is 192.168.10.0/24.  I moved one of the DC's into the server portion of the remote site.  When I connect using the WatchGuard VPN client I get assigned an address on the 192.168.113.0/24 subnet.  I can see all servers and access all machines on the .0.0/24 subnet without issue, when I try and hit the servers on the 10.0/24 subnet I get a few replies and then couple timeouts.  If I try a continuous ping I may get up to 12 replies before getting 2-3 timeouts and then replies again.  Also, if I run a continuous ping from my machine at the office (on the 0.0/24 subnet) I get all replies but will start getting some timeouts if someone connects via the WatchGuard VPN client.  
I am hoping I am just missing a step as this is becoming frustrating.
If anyone can provide any insight it would be greatly appreciated.
0
Comment
Question by:joeyj1970
  • 3
  • 2
5 Comments
 
LVL 90

Accepted Solution

by:
John Hurst earned 500 total points
ID: 41814708
You may need to turn NAT traversal ON. Also a site-to-site tunnel will use MAIN Mode. Mobile users use AGGRESIVE Mode. Make sure the mode is correctly set.
0
 

Author Comment

by:joeyj1970
ID: 41814747
Thank you John, I will give that a try tomorrow.
0
 
LVL 90

Expert Comment

by:John Hurst
ID: 41814855
Please let us know after you have tried. Thanks.
0
 

Author Comment

by:joeyj1970
ID: 41816652
John,  We switched to Aggressive mode and latency still existed.  Turns out they had something wrong on the Fortigate tunnel side.  Once they removed the Tunnel and reconfigured in a different manner, I no longer received any packet loss when remote.'
Thank you for the suggestion.
0
 
LVL 90

Expert Comment

by:John Hurst
ID: 41816685
Thanks for the update and I was happy to help
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

This article will review the basic installation and configuration for Windows Software Update Services (WSUS) in a Windows 2012 R2 environment.  WSUS is a Microsoft tool that allows administrators to manage and control updates to be approved and ins…
What to do when Windows Update is not working correctly? What tools can I use to detect the cause of the malfunction problem? What does this numeric error code mean? These and other questions that you have been asking in the past are answered here (…
In this Micro Tutorial viewers will learn how to use Boot Corrector from Paragon Rescue Kit Free to identify and fix the boot problems of Windows 7/8/2012R2 etc. As an example is used Windows 2012R2 which lost its active partition flag (often happen…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now