Solved

Connection timeouts with mobile vpn users

Posted on 2016-09-25
5
65 Views
Last Modified: 2016-09-26
We just setup a colocation and all connections from our main site to colocation site seem fine.  When remote user connects I start getting timeouts.  Here is the setup.
At main office we have a Watchguard router, at colocation is a Fortigate router.  The gateway and tunnels are setup for site to site between the 2 and it works.
At the main site on the DC, I have sites and services configured accordingly.  The main site subnet is 192.168.0.0/24 and the remote site is 192.168.10.0/24.  I moved one of the DC's into the server portion of the remote site.  When I connect using the WatchGuard VPN client I get assigned an address on the 192.168.113.0/24 subnet.  I can see all servers and access all machines on the .0.0/24 subnet without issue, when I try and hit the servers on the 10.0/24 subnet I get a few replies and then couple timeouts.  If I try a continuous ping I may get up to 12 replies before getting 2-3 timeouts and then replies again.  Also, if I run a continuous ping from my machine at the office (on the 0.0/24 subnet) I get all replies but will start getting some timeouts if someone connects via the WatchGuard VPN client.  
I am hoping I am just missing a step as this is becoming frustrating.
If anyone can provide any insight it would be greatly appreciated.
0
Comment
Question by:joeyj1970
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 95

Accepted Solution

by:
John Hurst earned 500 total points
ID: 41814708
You may need to turn NAT traversal ON. Also a site-to-site tunnel will use MAIN Mode. Mobile users use AGGRESIVE Mode. Make sure the mode is correctly set.
0
 

Author Comment

by:joeyj1970
ID: 41814747
Thank you John, I will give that a try tomorrow.
0
 
LVL 95

Expert Comment

by:John Hurst
ID: 41814855
Please let us know after you have tried. Thanks.
0
 

Author Comment

by:joeyj1970
ID: 41816652
John,  We switched to Aggressive mode and latency still existed.  Turns out they had something wrong on the Fortigate tunnel side.  Once they removed the Tunnel and reconfigured in a different manner, I no longer received any packet loss when remote.'
Thank you for the suggestion.
0
 
LVL 95

Expert Comment

by:John Hurst
ID: 41816685
Thanks for the update and I was happy to help
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The reason that corporations and businesses use Windows servers is because it supports custom modifications to adapt to the business and what it needs. Most individual users won’t need such powerful options. Here I’ll explain how you can enable Wind…
Let’s list some of the technologies that enable smooth teleworking. 
In this Micro Tutorial viewers will learn how to restore single file or folder from Bare Metal backup image of their system. Tutorial shows how to restore files and folders from system backup. Often it is not needed to restore entire system when onl…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question