DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

IKEv2 Connects OK when it is the only Tunnel Up

  • darren.gulliver
  • Topic Author
  • User
  • User
More
19 Mar 2018 16:33 #1 by darren.gulliver
IKEv2 Connects OK when it is the only Tunnel Up was created by darren.gulliver
Hi,
New here :)

I have 5 VPN Tunnels all set to use IKEv1, We introduced to new Tunnel to Azure using IKEv2 however it wont connect unless I disable and drop the other 5 profiles. After about 60 seconds the Azure Tunnel is up and I can connect to the Azure Server. Then I enable the other profiles and all is fine however after about an hour the Azure Tunnel then disconnects. I'm using Robocopy to backup our user shares and I see the files being copied to Azure so not sure why this connection keeps dropping.

The other thing we have noticed is that our Azure connection thinks its another profile for example our Azure connection is using index 6 but in connection management it says its index 2. Now index 2 is our Germany Office Tunnel.

so for Index 2 our server IP is set to 300.110.243.130, Remote Network IP: 192.168.68.0, Remote Gateway IP:192.168.68.1
Index 6 our server IP is set to 13.69.156.3, Remote Network IP: 10.50.0.0, Remote Gateway IP:10.50.0.254

Currently in connection management the following says its connected:
2( Germany ) IKEv2 IPsec Tunnel AES-SHA1 Auth via WAN1 13.69.156.3 192.168.68.0/24

But 13.69.156.3 is the Remote IP for Azure (Index 6) and 192.168.68.0/24 is the Virtual Network of the Germany connection (Index 2)

We have a Vigor2860n on Firmware 3.8.6_BT. The firmware we just upgraded for IKEv2 support.

Any Ideas?

Thanks in advance.
Darren

Please Log in or Create an account to join the conversation.

More
20 Mar 2018 21:15 #2 by ncollingridge
Replied by ncollingridge on topic Re: IKEv2 Connects OK when it is the only Tunnel Up
Personally, I suspect there is a big bug in the latest firmware regarding multiple tunnels. I have also found it impossible to get more than one tunnel to establish at the same time.

I have two profiles set up in LAN-LAN and only index 1 will connect. If I disable profile index 1 and just have profile index 2 enabled then 2 connects. If I then re-enable profile index 1 then it will connect and both are connected until one drops, but only one of the two tunnels will route correctly, index 1.

Anyone else have a similar experience?

Routers are BX2000 (3.8.1.8), the router connecting to profile index 1 is a 2860 (3.8.4.6_BT), and the one connecting to profile index 2 is a 2760 (3.8.7_BT).

Please Log in or Create an account to join the conversation.