#1  
Old April 11th, 2012, 01:45 AM
FXV538 FXV538 is offline
Junior Member
NETGEAR Newbie
 
Join Date: Dec 2010
Posts: 4
FXV538 is on a distinguished road
Default Site to Site VPN doesn't work

We have tree locations which are connected with a FXV538 VPN firewall

Location 1 is connected with location 2 and location 1 is also connected with location 3.

Only the connection from location 1 to location 3 isn't working while the other one is working fine.

The is a BT DSL modem in front of the netgear in location 3 which is set to the "DMZ plus" mode so the netgear does have a public ip adres itself.

The vpn log shows the following error:

VPN Log netgear Location 3:
Code:
2012 Apr 11 10:18:18 [FVX538] [IKE] accept a request to establish IKE-SA: 77.xxx.xxx.xxx_
2012 Apr 11 10:18:18 [FVX538] [IKE] Configuration found for 77.xxx.xxx.xxx._
2012 Apr 11 10:18:18 [FVX538] [IKE] Initiating new phase 1 negotiation: 81.xxx.xxx.xxx[500]<=>77.xxx.xxx.xxx[500]_
2012 Apr 11 10:18:18 [FVX538] [IKE] Beginning Identity Protection mode._
2012 Apr 11 10:18:49 [FVX538] [IKE] Invalid SA protocol type: 0_
2012 Apr 11 10:18:49 [FVX538] [IKE] Phase 2 negotiation failed due to time up waiting for phase1. _
2012 Apr 11 10:19:18 [FVX538] [IKE] Phase 1 negotiation failed due to time up for 77.xxx.xxx.xxx[500]. 3957fddc595436d2:0000000000000000_
VPN log location 1:
Code:
2012 Apr 11 11:41:10 [FVX538] [IKE] Configuration found for 81.xxx.xxx.xxx._
2012 Apr 11 11:41:10 [FVX538] [IKE] Initiating new phase 1 negotiation: 77.xxx.xxx.xxx[500]<=>81.xxx.xxx.xxx[500]_
2012 Apr 11 11:41:10 [FVX538] [IKE] Beginning Identity Protection mode._
2012 Apr 11 11:41:10 [FVX538] [IKE] Setting DPD Vendor ID_
2012 Apr 11 11:41:41 [FVX538] [IKE] Invalid SA protocol type: 0_
2012 Apr 11 11:41:41 [FVX538] [IKE] Phase 2 negotiation failed due to time up waiting for phase1. _
2012 Apr 11 11:42:10 [FVX538] [IKE] Phase 1 negotiation failed due to time up for 81.xxx.xxx.xxx[500]. ecea7f2695195062:0000000000000000_
2012 Apr 11 11:42:46 [FVX538] [IKE] Configuration found for 81.xxx.xxx.xxx._
2012 Apr 11 11:42:46 [FVX538] [IKE] Initiating new phase 1 negotiation: 77.xxx.xxx.xxx[500]<=>81.xxx.xxx.xxx[500]_
2012 Apr 11 11:42:46 [FVX538] [IKE] Beginning Identity Protection mode._
2012 Apr 11 11:42:46 [FVX538] [IKE] Setting DPD Vendor ID_
The configuration from the the netgear from location 2 and 3 are exactly the same except the ip adressen. Does someone know why loction 3 doesn't connect with location 1?
Reply With Quote
  #2  
Old April 11th, 2012, 06:39 AM
adit's Avatar
adit adit is offline
Moderator
NETGEAR Fanatic
 
Join Date: Nov 2006
Location: USA
Posts: 5,044
adit is on a distinguished road
Default Re: Site to Site VPN doesn't work

Check the settings in the IKE screens.
__________________
.
Forum Rules - Post Screenshots on ImageShack for Free - Firmware Upgrade Procedure
.
Online Subnet Calculator - LAN Subnets NOT to Use - SA Lifetime Guidelines - Hex/IP Converter
.
Free Netgear Support Online Trouble Ticket Submissions 1-888-NETGEAR 4,3 Netgear Knowledge Base
.
VPN Router Support, Interface Demos,and Marketing Pages:
.
SRX5308 S M - FVS336G S I I M - FVS318G S M - FVS318N S M - FVS338 S I I M - SRXN3205 S M -
VPNG01/5L S M - FVS318 S I I M - DGFV338B S I M - FVG318 S I I M - SSL312 S I M - FVX538 S I I
.
FVS114 - FVS124G - FVS328 - FVL328 - FWG114P - GPL Firmware Code - MyOpenRouter - VPNC Docs
.
Click Here for my VPN Client and Mode Config VPN Client Tutorials
.
ProSecure STM/UTM Appliance User Forum - Prosecure Marketing Website
.
.
Good Luck...ADIT

FYI - I am a Reseller and not employed by Netgear
Reply With Quote
  #3  
Old April 13th, 2012, 02:01 AM
FXV538 FXV538 is offline
Junior Member
NETGEAR Newbie
 
Join Date: Dec 2010
Posts: 4
FXV538 is on a distinguished road
Default Re: Site to Site VPN doesn't work

The IKE settings are oke (the other location is working fine). I managed to get the vpn working, there was a problem with the internet connection. Only the vpn disconnects after several hours, I have to recreate the policies several times to make it work. I tried different firmware versions but that didn't work.
Reply With Quote
  #4  
Old April 13th, 2012, 06:08 AM
jmizoguchi's Avatar
jmizoguchi jmizoguchi is offline
Senior Member
NETGEAR Fanatic
 
Join Date: Feb 2007
Location: Kentucky, USA
Posts: 89,328
jmizoguchi is on a distinguished road
Default Re: Site to Site VPN doesn't work

Are you using sa life of 86400?
__________________
VPN Case Study (www.vpncasestudy.com)
Our Second To None VPN Related Setup Case Study
"One Stop Solution To Your Netgear VPN Connectivity"
*Visit the site for Non-VPN related Doc & Links* [Windows & Mac user/support]

Most Other Useful Docs -"General Technical Documentation", "Router Reset", "Router Setup", "Print Server Tips", "Remote Admin"
"Wireless Tips"


Forum Policy

June Mizoguchi-i....@vpncasestudy.com
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -8. The time now is 04:12 AM.