L2TP VPN get disconnected after few minutes with [COOKIE] Invalid cookie, no sa found
Hi,
I've just setup an USG 110 and its L2TP VPN Server-Client role and am trying it.
It works well until the connection from my Mac gets disconnected with the following message in the logs of the USG : [COOKIE] Invalid cookie, no sa found [count = 2]
I've haven't tried with a Windows client yet. Anyone encountered this ?
Note : using VPN SSL it seems to work fine.
Thanks for your hints.
Edit 1 : have just tried on a Windows client for longer than my mac and it doesn't get disconnected, so there must be something on Apple devices.
I've just setup an USG 110 and its L2TP VPN Server-Client role and am trying it.
It works well until the connection from my Mac gets disconnected with the following message in the logs of the USG : [COOKIE] Invalid cookie, no sa found [count = 2]
I've haven't tried with a Windows client yet. Anyone encountered this ?
Note : using VPN SSL it seems to work fine.
Thanks for your hints.
Edit 1 : have just tried on a Windows client for longer than my mac and it doesn't get disconnected, so there must be something on Apple devices.
0
Comments
-
Just curious about 09:06:50 Peer not reachable. Is this log generated by MAC L2TP client connection?
0 -
@Hawaii,
I am unable to reproduce it on local lab with MAC os, please sent me your configuration file by private message.
0 -
Hi Hawaii,
the key message that is the probable error in your log is at:
21-04-02 09-06-50 Peer not reachable ... (usually source:ipv4:500 dest_peer ipv4:4500 )??
.... as a result of the previous [NOTIFY:R_U_THERE] ... request of the VPN peer
Would suggest you disable the Dead Peer Detection (DPD) on the VPN Gateway .
DPD is somewhat ye-olde-teck perhaps and is set by default.. good however for multiple WANs...
Refer here in these forums as someone else seems to have this issue.. follow the directions...:
https://businessforum.zyxel.com/discussion/1297/connection-lost-when-sending-big-files#latest
This should give you the stability you're looking for.
hth
warwick
Hong Kong
1
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight