cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
13922
Views
5
Helpful
24
Replies

RV042 site to site VPN with dynamic IP

Eli Hunter
Level 1
Level 1

I recently bought two RV042s to create a site to site VPN for a client.  I have several of these setups installed at other locations but this is the first version 3 hardware I've used.

It seems like the dynamic IP functionality of the VPN setup may not be working correctly.  I've verified all settings on each router match and have deleted/recreated the setup several times just to make sure.  Here's the logs from the router with a static IP.

Nov 29 06:49:51 2012 VPN Log (g2gips0): deleting connection 

Nov 29 06:49:51 2012 VPN Log added connection description (g2gips0) 

Nov 29 06:49:51 2012 VPN Log listening for IKE messages 

Nov 29 06:49:51 2012 VPN Log forgetting secrets 

Nov 29 06:49:51 2012 VPN Log loading secrets from '/etc/ipsec.d/ipsec.secrets' 

Nov 29 06:49:51 2012 VPN Log (g2gips0): cannot initiate connection without knowing peer IP address 

Nov 29 06:49:51 2012 VPN Log (g2gips0): cannot initiate connection without knowing peer IP address 

I've tried both dynamic IP + email and dynamic IP + FQDN to authenticate the router using the dynamic IP and both give the same error as above.

I did a firmware update hoping to fix PPPoE which seemed to be broken with a Netopia modem in bridge mode so both routers are on the latest firmware,

v4.2.1.02.

Any help would be appreciated

24 Replies 24

yeah, I have had trouble with the Dynamic + FDQN as well.  I have statics on most of the routers but there are a couple that are dynamic.  One I know for sure has changed in the last year but the tunnel came back up on its own after going down.  It looked like the RV042 corrected the local IP after a few minutes.  I'm not certain this will always happen.. 

Anyone out there know if the local IP will update if it is a dynamic address and it changes??

Yeah there definitely seems to be a bug in system. I too am interested in knowing if the router will automatically change the local IP address of the tunnel if the WAN ip changes. I just wished there was a IP by DNS resolved option for the local gateway too. (Though one would have hoped that that is what Dynamic + FDQN was meant to address ... to bad it does not function).

IS THERE A CISCO SUPPORT AGENT WHO COULD OPEN A TICKET FOR THIS ISSUE AS THIS DEFINITELY SEEMS TO EFFECTING MORE THAN A FEW PEOPLE AND IS DEFINITELY REPRODUCEABLE.

I second the request for a Cisco agent to look into this!

Hi Harry, I´ve seen your post and I want to apologize for the issues you are having, please call the Small Business Support Center to confirm if this is a bug. Please go here to find the phone number in your country:

https://www.cisco.com/en/US/support/tsd_cisco_small_business_support_center_contacts.html

Then I encourage you to share the answer with the community I hope you find this answer useful, and again sorry for the inconvenience

*Please mark the question as Answered or rate it so other users can benefit from it"

Greetings,

Johnnatan Rodriguez Miranda.

Cisco network support engineer.

“Please rate useful posts so other users can benefit from it” Greetings, Johnnatan Rodriguez Miranda. Cisco Network Support Engineer.

Hello, has this issue been resolved?

Regards,

Hi Harry

My name is Mehdi From Cisco Technical Support I want to clarify the different option on RV042 regarding the remote and local gateway I want to pick up your topology as example

When you want to configure the VPN it shoould be IP resolved by dns, why ?

Example :

Router (A) configured on WAN interface with Dyndns account
Router (B) configured on WAN interface with dyndns account

On router (A) the remote gateway configured with IP by dns resolved , it means the router (A) will resolve the domain name in this case event if the router (B) change the public IP address the router (A) he will learn the new Public IP so no disconnection when the router (B) change the IP address because Ruter (A) will learned with the domain name and this Tunnel is MAIN Mode and it can be initiate the tunnel from both site And Vice-Versa

For the option DynamicIP+FQDN

this option is used if you have one of the site with Public Dynamic IP and NO Dyndns account and you cannot use this option when you have on both router Dynamic IP without dyndns

Example :

Router(A) configured with static Public IP on WAN interface
Router(B) configured with DHCP on WAN interface (Dynamic IP)

when you configure the Router (A) with remote gateway as dynamic IP the Router(A) will work in Agressive mode (Responder becaue he cannot initial to unknown Public IP address ) waiting for the destination site to initiate the tunnel

Please mark the question as Answered or rate it so other users can benefit from it


Thanks
Mehdi

Confirmed Mehdi's resolution:

1) For Gateway Type, choose "IP Only". That will enable a drop-down.
2) In the drop-down, change the option from the default "IP Address" to "IP by DNS Resolved".
3) In the input field, enter your DDNS FQDN (ie: "router-a.dyndns.org")

Now your router will resolve the DDNS IP address and use it to make the connection. You will see the remote IP address (not the FQDN) on the VPN status page.

lucashmz1
Level 1
Level 1

No, I also have the same issue with RV042. Cisco seems to not care of their Small Business clients

I bought a RV320 to try to solve this issue, but it's worst that any router I've ever seen, because it has a huge bug in its firmware. The router starts to get unstable as IPSEC tunnels are in use, high latency and lost packets.

I don't have anymore ideias to deal with it

Hi Lucas,

My name is Mehdi from Cisco Technical Support I was posting already some explaination regarding the Remote gateway and Local Gateway regarding the RV042, please if you have any issue with RV320 regarding the VPN please share with us the topology we will help you

Thanks

Mehdi

thanks. I'm treating the RV042 issue with cisco support team. but we can work on RV320, the instability issue is going to be a little difficult to solve, but there's a minor bug that you can see. You can not add more than 19 character at VPN tunnel backup IP/Name (case number 628551041)

The instability we can measure it trough Ping Plotter, and we can find some jitters and latency degradated