MX85 drops anyconnect DTLS, only accepts TCP. Causes repeat disconnect/reconnect of vpn at startup

JacobS5
Just browsing

MX85 drops anyconnect DTLS, only accepts TCP. Causes repeat disconnect/reconnect of vpn at startup

Our MX85 drops UDP/DTLS connections, only responds to TCP/TLS. this seems to start after about a month of uptime and is fixed with a reboot.

  • I've confirmed the MX sees these packets, but ignores them and doesn't respond, showing udp 443 is open. The vpn then continues to work over tls
  • The MTU is 1500 and doesn't change pre & post reboot
  • This has been happening for months, always a reboot of the mx fix it.

anyone ran into this before?

6 Replies 6
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

What firmware version are you running?

JacobS5
Just browsing

19.1.8.1,  planning to upgrade to  MX 19.1.11 overnight. I looked through the bug fixes on the patch notes of this version, recent versions. Doesn't appear to be a known issue or something that has been solved yet.

Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

Have you opened a Support case? There are some fixes to the AnyConnect service in some of the newer releases.

 

If it's working for a while then stops working I would tend to think the service is stalling or crashing. Or, something else time in service related like port exhaustion, etc. Just a guess though. Support would be able to give a better answer after they look at your MX and the logs.

JacobS5
Just browsing

I had wondered if it was a memory leak or overutilization, but the support technicians I have spoken to have pointed out that utilization is normal. They haven't noticed noticed anything in the logs, only suggesting exploring mtu and upgrading firmware after mtu seems normal. The problem originated on 17.1.1, reoccured a month after upgrading to 18.1.1, now going to 19.1.1 am worried it will reappear again after a month.

 

I've only noticed that we see these dead peer detection logs when the DTLS drops and causes several disconnect/reconnects of the vpn client: Deleted DTLS tunnel[3515.181] from DB. Reason: DPD kill 

 

When the dtls drops without disconnect/reconnect there is no log for DPD kill

 

Is there a way to check if the process that listens for dtls connections is working & the port is listening? I am only connected to the meraki through the web gui, as far as i can tell, this model does not have any kind of way to connect to its cli.

PhilipDAth
Kind of a big deal
Kind of a big deal

Does your MX have the public IP address directly on its WAN interface, or is it sitting behind something NATing to it?

JacobS5
Just browsing

Nope, has the public ip on its Wan

Get notified when there are additional replies to this discussion.