Flapping AutoVPN

Angus
Comes here often

Flapping AutoVPN

Can someone help me understand why the AutoVPN flaps like this? I have numerous sites that are doing this. Their internet connections are solid with no packet loss. In the past, I have emailed support and they have done something their end to correct the issue. 

 

I'd prefer to prevent this from occurring than needing to managing it when it happens.  What can I do to prevent this from happening?

 

 

Angus_0-1659933700873.png

 

6 Replies 6
Jim_Liang
Meraki Employee
Meraki Employee

this usually happens at the ISP side, e.g. Site A & B are using different ISP providers that set some policies for some traffic cross carriers. 

Angus
Comes here often

So are you saying the AutoVPN only works when both sides are using the same ISP?

No. I was saying that crossing different ISPs would make the VPN connection unstable.

I have the same issue with my corpNetwork@home setup as the following.

You can see the tunnels for myself and my colleagues connecting to the office Hub were going up and down frequently. 

Jim_Liang_0-1660022763859.png

But this is a general challenge, may not be your case. 

One piece of advice is that you can add the peer IP as an uplink monitor destination on your MX, at least to see if there is packet loss.

Jim_Liang_1-1660023057697.png

 

Jim_Liang
Meraki Employee
Meraki Employee

Your logs showed the connection challenge with the Meraki VPN registry, not really the VPN tunnel between MXs.

therefore, it should not impact the actual traffic going through the VPN tunnel.

Jim_Liang_2-1660023318064.png

worse case, it may impact tunnel establishment for new VPN peers. 

 

Angus
Comes here often

Thanks @Jim_Liang just to confirm, the message I am seeing doesn't mean that the VPN tunnel is dropping, it is more an "internal" message about the registry that is controlling the AutoVPN service. Am I correct in saying this?

That's correct.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels