Improve Branch Office VPN Tunnel Availability

There are IPSec Branch Office VPN (BOVPN) installations in which all the settings are correct, but BOVPN connections do not always operate correctly. You can use the information below to help you troubleshoot your IPSec BOVPN tunnel availability problems. These procedures do not improve general BOVPN tunnel performance.

Most BOVPN tunnels remain available to pass traffic at all times. Problems are often associated with one or more of these three conditions:

  • One or both endpoints have unreliable external connections. High latency, high packet fragmentation, and high packet loss can make a connection unreliable. These factors have a greater impact on BOVPN traffic than on other common traffic, like HTTP and SMTP. With BOVPN traffic, the encrypted packets must arrive at the destination endpoint, be decrypted, and then reassembled before the unencrypted traffic can be routed to the destination IP address.
  • One endpoint is not a Firebox, or is an older Firebox or XTM device with older system software. Compatibility tests between new WatchGuard products and older devices are done with the latest software available for older devices. With older software, you could have problems that have been fixed in the latest software release.
    Because they are based on the IPSec standard, Firebox and XTM devices are compatible with most third-party endpoints. However, some third-party endpoint devices are not IPSec-compliant because of software problems or proprietary settings.
  • If there is a low volume of traffic through the tunnel, or if there are long periods of time when no traffic goes through the tunnel, some endpoints terminate the VPN connection. Fireboxes that run Fireware, and Firebox X Edge devices do not do this. Some third-party devices use this condition as a way to terminate tunnels that seem to be dead.

You can install the latest operating system software on all Fireboxes, but all of the other conditions in this list are out of your control. You can, however, take certain actions to improve the availability of the branch office VPN.

See Also

Monitor and Troubleshoot BOVPN Tunnels

Manual Branch Office VPN Tunnels