VPN tunnel uptime problem

Options
PeterUK
PeterUK Posts: 4,205 image  Guru Member
250 Answers 2500 Comments Friend Collector Eighth Anniversary
edited November 4 in Nebula

USG FLEX 700H V1.36(ABZI.0)

So I don't normally look at Nebula but now and then I log in to view some things like the VPN usage and connectivity and I'm sure the last time I looked when I had three tunnels that are local it showed solid green for all of them but I added a 4th and check over some days and some red was showing I through what was the cause was incorrect local/remote ID but no was not that. I then disabled the 4th tunnel and still there was a drop and all at the same time for the three tunnels.

So now I have enabled the 4th and added a 5th to do a ping to see if the ping drop or does not drop when Nebula show red as a drop.

Screenshot 2025-11-04 113709.png

The link from/to FLEX700H and Zyxell 110 gone through three switches and I have checked port up and down logs all showed clear.

«1

All Replies

  • PeterUK
    PeterUK Posts: 4,205 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited November 4

    Caught it in the ack!

    So this looks to be a Nebula problem because my ping test was running fine down test tunnel all other tunnels were fine but Nebula says they are all disconnected when not.

    Screenshot 2025-11-04 201809.png

    There might be two random problems at play because the above show disconnected so you would that think that would show in connectivity but not this time? maybe the next time it happens it will show?

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,093 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @PeterUK

    The discrepancy you're seeing (where your ping test is successful but the Nebula dashboard shows "disconnected") is due to the fact that the VPN status on the Nebula Control Center (NCC) is not displayed in real-time.

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,205 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Hi Melen

    Even if its not real-time the last heartbeat which for the VPN tunnels looks to be 5 minutes should correctly show if it tunnels are connected or not.

    dis.png
  • PeterUK
    PeterUK Posts: 4,205 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Hmm… its now been 24hr and the connectivity is solid green along with the other tunnels

    Screenshot 2025-11-06 135953.png
  • Zyxel_Melen
    Zyxel_Melen Posts: 4,093 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @PeterUK

    Have you disable/enable the VPN tunnel for last 24 hr? If not, the issue could relate to the VPN status report during disable/enable the VPN tunnel. Could we have a remote replicate for this issue? During the replicate, we will also collect the needed logs to investigate this issue.

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,205 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    No I have not disabled or enable the tunnel for the last 24hr, could someone your end of fixed something?

    Zyxel Support Access is enabled on Nebula for Organization _ Site USG FLEX 700H

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,093 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    This is because the disconnect period has passed over the last 24 hours. For the past 24 hours, there's been no disconnect issue; the VPN status displays all green.

    Therefore, I assume this issue could relate to the VPN status report during/after disabling/enabling the VPN tunnel. Please let us know if you allow us to have a remote replication, thanks.

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,205 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Ok sure you can remote replication the issue if needed.

    Thanks

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,093 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @PeterUK

    We noticed that there has some error logs related with netconf, the protocol for Zyxel devices communicate with Nebula, which could cause some device's data can't be sent to Nebula server. To fix it, could you help to reboot the firewall? We will access to check further after rebooting.

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 4,205 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary

    Ok its been rebooted

Nebula Tips & Tricks