Avatar of Robert Wagstaff
Robert Wagstaff
Flag for United States of America asked on

VPN Tunnel Stops Working Cisco RV130W

I have two networks connected with a VPN Site-to-Site Tunnel using two Cisco RV130W Routers. I have enabled NAT Traversal on both sides in order for communication across ports to work at all. (see previous post https://www.experts-exchange.com/questions/29011836/Bizarre-IP-Address-Port-Blocking-Windows-7.html) Now, the tunnel stops working all together after a few days. No pinging is successful at all. I disconnected and reconnected one side of the tunnel and it is back up and running now.

Any ideas on how to create a more stable connection??

Thank you
CiscoVPN* NAT

Avatar of undefined
Last Comment
Craig Beck

8/22/2022 - Mon
John

Did you try updating firmware on the Cisco 130W routers. I am showing RV130X_FW_1.0.3.22 for a couple of these I have at clients.
Robert Wagstaff

ASKER
I show both are running FW: 1.0.3.16  Am I correct to believe that these site-to-site VPN tunnels should work flawlessly for months on end? This is honestly my first VPN tunnel and it just seems so flaky and unstable.
ASKER CERTIFIED SOLUTION
John

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Robert Wagstaff

ASKER
I will consider that however if firmware upgrade goes south I am 3 hours away so I will need to time it right.

Thank you for your help in this matter....again! =)
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
John

I was happy to help and I will keep watching.  Thank you so much.
Craig Beck

Forgive me, but have you actually tried the firmware upgrade and confirmed that to be the solution?
Robert Wagstaff

ASKER
I just spent an hour on the phone with Cisco. Instability remains. Actually turned OFF NAT Traversal as that is supposed to be used when you have a router in front of the Cisco router which I do not. Now even stranger behavior....I can access the port on the remote server but I cannot ping it. WTF!!!!!!!! I am afraid to do the firmware upgrades unless I am on site. I may be forced to however if the communication keeps dropping.

Very frustrated.
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
John

I think Firmware should be updated if you can because it is behind a version or two.
Robert Wagstaff

ASKER
Yah I assume that would be wise. I just can imagine Cisco releasing a product that is less than a year old with a bad firmware. It's not like VPN tunnels are a new thing.
John

I know I had an issue (as noted above) that newer firmware fixed.

Also your tunnel stays up for a few days and that means the tunnel parameters are very likely (99%) correct.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
Robert Wagstaff

ASKER
But seriously why can't I ping 192.168.12.31 which is on the other side of the tunnel but yet telnet 192.168.12.31 80 works fine. Also, I can ping and telnet 192.168.12.34 without a problem. I had a constant ping going on .31 when all of a sudden it timed out. I am so confused.
John

It is proper operation then none (as you describe above) that makes me think a problem inside the RV130W. I have several of these at another client not giving a lick of trouble.
Robert Wagstaff

ASKER
I took your advice and upgraded the firmware on both routers to v1.0.3.22. The web interface seems much more responsive and the communication across the VPN tunnel is going strong right now. Need to see if it is stable over a week or so. Thank you
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
John

Thank you for the update. Good news!
Craig Beck

There's lots of variables which can affect VPN traffic. See how the firmware goes but I'd expect it to be down to a network issue rather than firmware.
Robert Wagstaff

ASKER
Ok here's the latest....The VPN Tunnel connection seemed to be running smoothly for a couple days as I was testing connecting to the port using "PORTQRY" and writing it to a log every 1 minute. Things went south however and traffic started to fail. I bounced the VPN tunnel and communication started up again with seemingly no problems. Not sure what to do other than bounce the connection daily. Any ideas???
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
John

Two days of solid connection means that the Connection Parameters are good. The firmware you have is the newest and working on my units.

So then is there a hardware issue?  or an environment problem (power supply to the unit, or internet supply to the unit)?

Is the unit properly ventilated and not overheating?
Craig Beck

It will be a network issue.  Simply reloading the boxes or bouncing the interface does nothing for overheating, etc.

There's lots of issues that can affect IPSec tunnels... MTU, latency, clock issues, routing, etc.

I'd check the logs on the boxes to see if they reveal anything.