Hey Stefan, We don't see any log messages like that, all we see on the RV042 are successful DPD messages and successful negotiations. On the Watchguards, we see the same success messages as well as ping traffic outbound to the RV042, but nothing incoming. Last night, one of the tunnels began working again (randomly). I'm not sure how long it will stick around, I started an infinite ping just to make sure there is some traffic going over the link to try and keep it up (although DPD should help with that anyways). Thanks for the response!
... View more
Hello, I have two site to site VPN tunnels between a RV042 (which is behind another router, so NAT'd) and two different Watchguard XTM510s (public internet facing). This connection was working up until a month ago, when for some reason it crashed and now it will not come back up completly For both tunnels, traffic only seems to be flowing one way. It appears as though the devices complete both phase 1 and phase 2 negotiations, the tunnels come up almost instantly, they just don't transfer traffic. Phase 1 settings on all: Agressive mode IKE Encryption: AES128 Authentication: SHA1 DH Group 1 Lifetime: 28800s (RV042) / 8 hours (XTMs) Phase 2 settings NO PFS Encryption: AES128 Auth: SHA1 DH Group 1 Lifetime: 28800s / 8 hours, no traffic expiration I have NAT traversal and DPD turned on. Both sides show the tunnel as active, the correct routes show up in the routing tables, but I can't ping across it and the data counters on the Watchguard devices show traffic going one way only. The logs on all devices show the DPD packets being sent and recieved, so I know that the devices can talk, it's just that last little bit that isn't working. I've tried completely recreating the tunnels, power cycling everything, different encryption schemes, different keys, and different options, but I can not get these tunnels to work. If I could just get one tunnel to work I can route traffic where it needs to go (there is a tunnel between the Watchguards that is functioning perfectly). Does anyone have any ideas?
... View more