10-24-2019 09:53 AM - edited 10-24-2019 10:17 AM
Hi,
I am experiencing a rather strange problem with the "new" ISR 1101 IoT router.
Our Setup:
VPN Hub / Gateway with dynamic Crypto Map: 2x ASA 5545-X with 8.9.4(10) HA
2 ISPs with static IP ranges, nothing out of the ordinary
Interfaces are IKEv2 enabled
VPN Spokes: 150x ISR 1101 with p-lte-gb Module (WP7607) and 2 different WISP SIM Cards. (FW 16.11.1)
Public/Private dynamic IPs, NAT-T, DPD, IKEv2, basic Tunnel Mode IPSEC, no VTI, etc.
10.66.1.1 -> ASA -> ISP -> WISP -> Cell0/1/0 -> ISR1101 -> vlan 1 -> 10.48.199.254/24
Since overall everthing is working fine except for one little detail,
I didn't want to spam the community with the full config c&p right away.
If I am pinging the router 10.48.199.254 from 10.66.1.1 I get very unstable response times:
Antwort von 10.48.4.254: Bytes=32 Zeit=319ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=27ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=27ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=182ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=138ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=32ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=48ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=37ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=27ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=32ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=191ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=29ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=98ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=27ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=32ms TTL=254
Antwort von 10.48.4.254: Bytes=32 Zeit=32ms TTL=254
Up to 50 ms would be normal for this type of connection, but very regulary the latency shoots up to a few hundret ms.
Now this wouldn't puzzle me (MTU, unstable connection,etc) if it were not for the fact, that there is only one environmental situation that causes this to happen:
Ping from ISR1101 vlan1 to Inside ASA (LTE, WISP1&2, idle and traffic) -> normal,stable
Ping from ISR1101 vlan1 to Inside ASA (WCDMA, WISP1&2, idle and traffic) -> normal,stable
Ping from ISR1101 vlan1 to Inside ASA (TestWiredConnection, idle and traffic) -> normal,stable
Ping from Public ISR1101 to Public ASA (WCDMA/LTE, WISP1&2, idle and traffic) -> normal, stable
Ping from Public ASA to Public ISR1101 (WCDMA/LTE, WISP1&2, idle and traffic) -> normal, stable
Ping from Inside ASA to ISR1101 vlan 1 (WCDMA, WISP1&2, idle and traffic) -> normal, stable
Ping from Inside ASA to ISR1101 vlan 1 (Wired Test, idle and traffic) -> normal, stable
Ping from ISR1101 vlan1 to Inside ASA (LTE, WISP1&2, with background traffic) -> normal,stable
Ping from ISR1101 vlan1 to Inside ASA (LTE, WISP1&2, idle, no backgroundtraffic) -> HIGH Latency Spikes
As soon as the IPSEC Line is loaded with traffic the spikes vanish and latency even goes further down to 20-30ms.
Has anybody experienced such a problem before?
10-24-2019 11:16 AM
Hello,
strange indeed, as you would expect the opposite to happen (response times going up when the link is loaded)...
When you do a traceroute rather than a ping, can you get an indication of where in the path the latency occurs ?
10-24-2019 11:30 AM
Hi, thank for the reply.
Unfortunately, tracroute doesn't provide any additional information since there is no
additional hop between ASA and Router VLAN (logically speaking) while using the IPSEC tunnel.
Using the public network path, the problem doesn't occure.
I've also done some additional testing and it doesn't matter how the Cellular interface is put under stress.
I'm pinging through the tunnel -> high latency spikes, as soon any a 3rd device (even located on the internet)
sends big icmp requests (eg 1400) to the public Cellular IP in order to generate traffic, everything normalizes.
Currently my only suspicion would be some kind of strange buffer/power scheduling problem, that doesn't properly detect ipsec packets in inbound direction.
10-24-2019 12:21 PM
Hello,
can you post the configs of the ASA and the ISR ?
10-24-2019 01:18 PM - edited 10-24-2019 01:36 PM
Router Config:
ASA Config:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide