VPN Tunnel Stops Working Cisco RV130W

Robert Wagstaff
Robert Wagstaff used Ask the Experts™
on
I have two networks connected with a VPN Site-to-Site Tunnel using two Cisco RV130W Routers. I have enabled NAT Traversal on both sides in order for communication across ports to work at all. (see previous post https://www.experts-exchange.com/questions/29011836/Bizarre-IP-Address-Port-Blocking-Windows-7.html) Now, the tunnel stops working all together after a few days. No pinging is successful at all. I disconnected and reconnected one side of the tunnel and it is back up and running now.

Any ideas on how to create a more stable connection??

Thank you
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
Did you try updating firmware on the Cisco 130W routers. I am showing RV130X_FW_1.0.3.22 for a couple of these I have at clients.
Robert WagstaffIT Consultant

Author

Commented:
I show both are running FW: 1.0.3.16  Am I correct to believe that these site-to-site VPN tunnels should work flawlessly for months on end? This is honestly my first VPN tunnel and it just seems so flaky and unstable.
Business Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018
Commented:
I have a Cisco 325 VPN router here and the tunnels are fine for long periods of time.

I did have a firmware issue with this Cisco 325 that affected tunnels. I went back a version to get stability and then forward two versions when a newer one came out.

So yes, I do suggest (carefully) upgrading firmware.
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Robert WagstaffIT Consultant

Author

Commented:
I will consider that however if firmware upgrade goes south I am 3 hours away so I will need to time it right.

Thank you for your help in this matter....again! =)
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
I was happy to help and I will keep watching.  Thank you so much.
Top Expert 2014

Commented:
Forgive me, but have you actually tried the firmware upgrade and confirmed that to be the solution?
Robert WagstaffIT Consultant

Author

Commented:
I just spent an hour on the phone with Cisco. Instability remains. Actually turned OFF NAT Traversal as that is supposed to be used when you have a router in front of the Cisco router which I do not. Now even stranger behavior....I can access the port on the remote server but I cannot ping it. WTF!!!!!!!! I am afraid to do the firmware upgrades unless I am on site. I may be forced to however if the communication keeps dropping.

Very frustrated.
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
I think Firmware should be updated if you can because it is behind a version or two.
Robert WagstaffIT Consultant

Author

Commented:
Yah I assume that would be wise. I just can imagine Cisco releasing a product that is less than a year old with a bad firmware. It's not like VPN tunnels are a new thing.
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
I know I had an issue (as noted above) that newer firmware fixed.

Also your tunnel stays up for a few days and that means the tunnel parameters are very likely (99%) correct.
Robert WagstaffIT Consultant

Author

Commented:
But seriously why can't I ping 192.168.12.31 which is on the other side of the tunnel but yet telnet 192.168.12.31 80 works fine. Also, I can ping and telnet 192.168.12.34 without a problem. I had a constant ping going on .31 when all of a sudden it timed out. I am so confused.
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
It is proper operation then none (as you describe above) that makes me think a problem inside the RV130W. I have several of these at another client not giving a lick of trouble.
Robert WagstaffIT Consultant

Author

Commented:
I took your advice and upgraded the firmware on both routers to v1.0.3.22. The web interface seems much more responsive and the communication across the VPN tunnel is going strong right now. Need to see if it is stable over a week or so. Thank you
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
Thank you for the update. Good news!
Top Expert 2014

Commented:
There's lots of variables which can affect VPN traffic. See how the firmware goes but I'd expect it to be down to a network issue rather than firmware.
Robert WagstaffIT Consultant

Author

Commented:
Ok here's the latest....The VPN Tunnel connection seemed to be running smoothly for a couple days as I was testing connecting to the port using "PORTQRY" and writing it to a log every 1 minute. Things went south however and traffic started to fail. I bounced the VPN tunnel and communication started up again with seemingly no problems. Not sure what to do other than bounce the connection daily. Any ideas???
JohnBusiness Consultant (Owner)
Most Valuable Expert 2012
Expert of the Year 2018

Commented:
Two days of solid connection means that the Connection Parameters are good. The firmware you have is the newest and working on my units.

So then is there a hardware issue?  or an environment problem (power supply to the unit, or internet supply to the unit)?

Is the unit properly ventilated and not overheating?
Top Expert 2014

Commented:
It will be a network issue.  Simply reloading the boxes or bouncing the interface does nothing for overheating, etc.

There's lots of issues that can affect IPSec tunnels... MTU, latency, clock issues, routing, etc.

I'd check the logs on the boxes to see if they reveal anything.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial