11-29-2012 07:02 AM
I recently bought two RV042s to create a site to site VPN for a client. I have several of these setups installed at other locations but this is the first version 3 hardware I've used.
It seems like the dynamic IP functionality of the VPN setup may not be working correctly. I've verified all settings on each router match and have deleted/recreated the setup several times just to make sure. Here's the logs from the router with a static IP.
Nov 29 06:49:51 2012 VPN Log (g2gips0): deleting connection
Nov 29 06:49:51 2012 VPN Log added connection description (g2gips0)
Nov 29 06:49:51 2012 VPN Log listening for IKE messages
Nov 29 06:49:51 2012 VPN Log forgetting secrets
Nov 29 06:49:51 2012 VPN Log loading secrets from '/etc/ipsec.d/ipsec.secrets'
Nov 29 06:49:51 2012 VPN Log (g2gips0): cannot initiate connection without knowing peer IP address
Nov 29 06:49:51 2012 VPN Log (g2gips0): cannot initiate connection without knowing peer IP address
I've tried both dynamic IP + email and dynamic IP + FQDN to authenticate the router using the dynamic IP and both give the same error as above.
I did a firmware update hoping to fix PPPoE which seemed to be broken with a Netopia modem in bridge mode so both routers are on the latest firmware,
v4.2.1.02.
Any help would be appreciated
01-08-2013 12:58 AM
yeah, I have had trouble with the Dynamic + FDQN as well. I have statics on most of the routers but there are a couple that are dynamic. One I know for sure has changed in the last year but the tunnel came back up on its own after going down. It looked like the RV042 corrected the local IP after a few minutes. I'm not certain this will always happen..
Anyone out there know if the local IP will update if it is a dynamic address and it changes??
01-08-2013 01:10 AM
Yeah there definitely seems to be a bug in system. I too am interested in knowing if the router will automatically change the local IP address of the tunnel if the WAN ip changes. I just wished there was a IP by DNS resolved option for the local gateway too. (Though one would have hoped that that is what Dynamic + FDQN was meant to address ... to bad it does not function).
IS THERE A CISCO SUPPORT AGENT WHO COULD OPEN A TICKET FOR THIS ISSUE AS THIS DEFINITELY SEEMS TO EFFECTING MORE THAN A FEW PEOPLE AND IS DEFINITELY REPRODUCEABLE.
01-08-2013 01:17 AM
I second the request for a Cisco agent to look into this!
01-08-2013 05:45 AM
Hi Harry, I´ve seen your post and I want to apologize for the issues you are having, please call the Small Business Support Center to confirm if this is a bug. Please go here to find the phone number in your country:
https://www.cisco.com/en/US/support/tsd_cisco_small_business_support_center_contacts.html
Then I encourage you to share the answer with the community I hope you find this answer useful, and again sorry for the inconvenience
*Please mark the question as Answered or rate it so other users can benefit from it"
Greetings,
Johnnatan Rodriguez Miranda.
Cisco network support engineer.
11-11-2013 03:35 PM
Hello, has this issue been resolved?
Regards,
12-24-2013 05:16 AM
Hi Harry
My name is Mehdi From Cisco Technical Support I want to clarify the different option on RV042 regarding the remote and local gateway I want to pick up your topology as example
When you want to configure the VPN it shoould be IP resolved by dns, why ?
Example :
Router (A) configured on WAN interface with Dyndns account
Router (B) configured on WAN interface with dyndns account
On router (A) the remote gateway configured with IP by dns resolved , it means the router (A) will resolve the domain name in this case event if the router (B) change the public IP address the router (A) he will learn the new Public IP so no disconnection when the router (B) change the IP address because Ruter (A) will learned with the domain name and this Tunnel is MAIN Mode and it can be initiate the tunnel from both site And Vice-Versa
For the option DynamicIP+FQDN
this option is used if you have one of the site with Public Dynamic IP and NO Dyndns account and you cannot use this option when you have on both router Dynamic IP without dyndns
Example :
Router(A) configured with static Public IP on WAN interface
Router(B) configured with DHCP on WAN interface (Dynamic IP)
when you configure the Router (A) with remote gateway as dynamic IP the Router(A) will work in Agressive mode (Responder becaue he cannot initial to unknown Public IP address ) waiting for the destination site to initiate the tunnel
Please mark the question as Answered or rate it so other users can benefit from it
Thanks
Mehdi
03-15-2018 02:37 PM - edited 03-15-2018 02:37 PM
Confirmed Mehdi's resolution:
1) For Gateway Type, choose "IP Only". That will enable a drop-down.
2) In the drop-down, change the option from the default "IP Address" to "IP by DNS Resolved".
3) In the input field, enter your DDNS FQDN (ie: "router-a.dyndns.org")
Now your router will resolve the DDNS IP address and use it to make the connection. You will see the remote IP address (not the FQDN) on the VPN status page.
12-19-2013 02:27 PM
No, I also have the same issue with RV042. Cisco seems to not care of their Small Business clients
I bought a RV320 to try to solve this issue, but it's worst that any router I've ever seen, because it has a huge bug in its firmware. The router starts to get unstable as IPSEC tunnels are in use, high latency and lost packets.
I don't have anymore ideias to deal with it
12-24-2013 05:22 AM
Hi Lucas,
My name is Mehdi from Cisco Technical Support I was posting already some explaination regarding the Remote gateway and Local Gateway regarding the RV042, please if you have any issue with RV320 regarding the VPN please share with us the topology we will help you
Thanks
Mehdi
12-24-2013 12:16 PM
thanks. I'm treating the RV042 issue with cisco support team. but we can work on RV320, the instability issue is going to be a little difficult to solve, but there's a minor bug that you can see. You can not add more than 19 character at VPN tunnel backup IP/Name (case number 628551041)
The instability we can measure it trough Ping Plotter, and we can find some jitters and latency degradated
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide