Page 1 of 1

Question about ipsec tunnel once established

Posted: Wed Jan 14, 2015 11:03 am
by Nova
Good day,

I would like to know, why sometimes when I create an Ipsec tunnel it creates two or more tunnels with the same ips, sometimes after few seconds sometimes after few hours.

For example in this case it create first the 1-3 tunnel, then the 2-4, (and the 2 with both algorithm none ???)

Image
The tunnel "works", when I do ping the 2-4 are the ones up.
Image

When I make more than one tunnel, it gets a bit chaotic.

Someone had the same problem? Or knows why it could happen?

Also, I have the problem that after x hours the tunnel breaks and the only solution I have is to kill connections. Now is ok because I have only one, but in the case I have 2 or 3 i would have to kill all the connections to make one work, anyone knows why?

In this case the connection is between Mikrotik 6.24 and Fritzbox.

Any help would be appreciated, thank you

Re: Question about ipsec tunnel once established

Posted: Thu Apr 09, 2015 1:15 pm
by lenart
Did you manage to solve this issue? I've had the same experience. I've been tinkering with this problem for a while now and I've found a solution that works in my particular case. I've put the responsibility of the creation of the tunnel on the Fritzbox by setting the option
send-initial-contact=no
. That has given me a connection that's been up without any issues for the past 12 hours with only two entries in the 'Installed SA' list (my tunnel).