cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
635
Views
0
Helpful
3
Replies

Cisco ISR4331 - IPsec tunnel connectivity issue

Richardkm
Level 1
Level 1

Hi!

I have a managed router from my ISP with a dedicated fiber connection 500/500.

I've recently requested for a site2site VPN to be configured towards one of my cloud providers.

They've configured it and I mapped the shared drive successfully and the data can be transferred from my computer via the IPsec tunnel.

However, for the duration of the transfer, my internet does not work. Pings time out, pages don't load and nothing works except for the data transfer. The transfer goes at about 150 Mbit rate and is consistent.

The internet, pings and everything else returns to normal as soon as the transfer finishes.

As far as I've been told, I have a booster license to allow for my 500/500 Mbit connection to work and an additional Security license for my IPsec to work. The ISR4331 has the latest firmware on it.

Several teams have been working at this issue for almost a month now. I've been told that several people are CCIE level experts and they have not been able to fix this and I'm angry at this point.

Unfortunately, I cannot do anything myself on the router side, but I can try and get you the data from them if they are willing to provide.

We've tested on several devices, the issue persists, so it's not my computer or my network card.

Any thoughts would be VERY much appreciated at this point.  TellTims Survey

3 Replies 3

during the transfer check the CPU memory utilize the give us hint what happen during this period.

please also share config

Hi

 Just trying to understand your scenario. If you can share the topology, would be easier.

You mention this:

"I've recently requested for a site2site VPN to be configured towards one of my cloud providers."

 

Site to Site VPN is stablished between two devices directly.  Just to keep this in mind.

 

Then, you said:

"However, for the duration of the transfer, my internet does not work. Pings time out, pages don't load and nothing works except for the data transfer. The transfer goes at about 150 Mbit rate and is consistent."

 

Here I got confuse. When you say "my internet" you mean the internet of you PC, correct?  But, is it your PC the only device connected to this VPN?  I mean, Site to Site is meant to interconnect to Sites. Inside a site it is expected to have router, switches, etc.

 

Which makes me wonder....Are you not reffering to a Client to Site VPN instead?  

Or your machine is the only machine connected to this ISR4331?

 

If you are using UDP for file transfer, and no rate limit is configured, it can consume all the internet link just like happen with some Torrent.

 UDP does not need ACK like TCP, so, it  can crash a link.

 

 

Rich R
VIP
VIP

Very hard to diagnose without seeing specifics from the router like config and licensing details.

As requested above router config would be a starting point.

"ISR4331 has the latest firmware on it." - what version is it running?

Is there any QoS configured on the router?

Does your ISP have any QoS configured?

"As far as I've been told, I have a booster license to allow for my 500/500 Mbit connection to work and an additional Security license for my IPsec to work" - smart licensing enabled or not?  The commands needed will depend on whether it's smart or not and which version of IOS-XE it's running.

"show ver" will give a summary of IOS and license info as well as throughput details: The current throughput level is XXXXXXXX kbps

"sh platform software cerm-information" will show whether the export-controlled rate-limit is applied (HSECK9 license disables this)