Ping over VTI Destination unreachable over time

PeterUK
PeterUK Posts: 3,118  Guru Member
Community MVP 2500 Comments Sixth Anniversary 100 Answers
edited July 22 in USG FLEX H Series

USGFLEX200HV1.21(ABWV.0)

Setup is USG60W

LAN2 192.168.254.9 255.255.255.248

VLAN 55 192.168.55.1 255.255.255.0

VTI_test

IP 192.168.254.10

Pre-Shared Key 12345678

Phase 1 AES128 SH256 DH2

SA Life Time 300

Phase 2 AES128 SH1 DH2

SA Life Time 180

VTI IP 192.168.255.43 255.255.255.240

FLEX200H

Ge3 WAN3 192.168.254.10 255.255.255.248 gateway 192.168.254.9

P4 VLAN47192.168.255.39 255.255.255.240

VTI Route-based

IP 192.168.254.9

Pre-Shared Key 12345678

Phase 1 AES128 SH256 DH2

SA Life Time 300

Phase 2 AES128 SH1 DH2

SA Life Time 180

VTI IP 192.168.255.42 255.255.255.240

Nailed-up

routing rule

incoming VLAN47

Destination192.168.55.12

service ICMP

Next hop VTI

SNAT none

When pinging from192.168.255.40 to 192.168.55.12 over the VTI the FLEX200H will sometime do a Destination unreachable.



All Replies

  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    So I might of jumped the gun on this along with this


    https://community.zyxel.com/en/discussion/22135/speeded-up-sa-life-time-site-to-site-local-test-tunnel-drops-does-not-reconnect#latest

    and the manual is clear on this:
    SA Life Time Set how often the Zyxel Device renegotiates the IKE SA. A short SA life time increases security, but renegotiation temporarily disconnects the VPN tunnel. The value you set for the SA life time in Phase 1 Settings should be greater than or equal to the value you set for the SA life time in Phase 2 Settings.

    So I'm seeing it happen every 10 minutes yet my Phase 1 is every 300 which is 5 minutes so you would think it would happen every 5 minutes so changed that back to 86400 but with Phase 2 is every 180 seconds no problem so its when Phase 1 has to renegotiation along with Phase 2 which there is a delay causes a drop out.

  • Zyxel_Kay
    Zyxel_Kay Posts: 830  Zyxel Employee
    Second Anniversary 500 Comments 100 Answers Zyxel Certified Network Engineer Level 2 - Security

    Hi @PeterUK

    After reviewing your configuration, it appears that there is an IP address overlap between VLAN47 and the VTI interface on your FLEX200H device. The overlapping IP range (192.168.255.32/28, covering IPs 192.168.255.33 to 192.168.255.46) can cause traffic routing issues, which might explain the intermittent "Destination unreachable" responses you are seeing when pinging across the VTI.

    To resolve this, we recommend changing the VLAN IP subnet to a different segment to eliminate the overlap. After making this change, please test the connection again to see if the issue persists.

    Let us know if this resolves the problem or if you need further assistance.

    Kay

    Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L

  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    edited August 22

    Yes but also no as I will explain but this problem was setting the SA life time low causing the VPN to renegotiates Phase 1 and Phase 2 which there is a delay causes a drop out.

    So ok let start with the way I have it setup I can ping 192.168.55.12 and the Flex can DNS over VTI

    You want me to change VLAN47 subnet on Flex OK I change to 192.168.25.39/28 I can DNS (note I do “cmd dns proxy clear-cache” on the Flex) because its from VTI IP 192.168.255.42 but now I can't ping 192.168.55.12 so on the USG60W I change VTI IP to 192.168.25.43 now I can ping 192.168.55.12 but can't DNS.

  • PeterUK
    PeterUK Posts: 3,118  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    edited August 22

    delete