Question
IPSEC VPN Tunnels going offline
I just implemented my 200A over the weekend... and for the most part everything went really well... had a few rules that I missed that I cleaned up on Monday morning. However I have noticed that some tunnels are not as stable as I like. I have about two dozen branch offices that connect in to this 200A, most of them are running WatchGuard SOHO 6tc units. I have upgraded the firmware on all of the SOHOs (thought that that might help) but some of the tunnels are still flakey. About 4 of these sites so far have been upgraded to Fortigate 60s. Those tunnels are quite stable. All of the sites have the exact same configuration. Phase I Aggressive Mode key life = 79200 seconds (phase 1 and phase 2) and 0 bytes NAT Traversal is on Dead Peer Detection is on Phase II Replay detection is on PFS is on Key life = 79200 Auto keep alive is on The rest of the configs (encryption, etc) match up on both ends. The odd part is that not all of the tunnels are having issues. Two of the sites (running SOHOs) will drop within a few minutes if I stop pinging a unit on their end. I can usually bring the tunnels up again but without a stream of data... it will drop again (very annoying). My PC is constantly pinging a few sites for now just to keep the tunnels up but I would like to get away from this. I thought at first that it might be the NAT traversal... but according to WG, the SOHOs support this feature. I don' t see anywhere where I can turn it on or off... but the config file from the unit does show options for NAT Traversal and it does appear to be enabled. I have also checked for a corelation between hardware or anything else at problem sites but haven' t found anything. Now I am thinking it might be the keylife... I saw here that some people reported better performance with a shorter keylife. Not sure how that would be... but at this piont I am willing to try anything. Thankfully I have a fully functioning WG SOHO here that I can use for testing. I just wanted to know if anyone else has come across this and / or if anyone had any suggestions. Please let me know! Thank you
