Greetings all,
I've got two D-Link routers: a DFL-800 and a DFL-210. They form a LAN-to-LAN IPSEC tunnel that link our two offices across the country.
It seems that every month or so, the link is severed and not reestablished. This is curious because both routers are set to automatic Keep-Alive. When the problem occurs, one router will have an active SA in the IPSec Status section, while the other will not. The only way I've found to correct the problem is to restart the until that claims to have an active SA. Then the VPN is automatically reestablished and all is right again.
Due to the time difference, this occassioanlly happens when I am asleep and unable to correct the problem, causing members of one office to be unable to access resources of the other. So while the problem is infrequent, it's critical for me to correct.
I've re-examined both devices' IPSEC settings, and found that they were identical except for two items. a) Only one router had "Dead Peer Detection" turned on. I've now made sure both units have this item checked. b) There was a slight discrepancy between the packet sizes in the "Routing" tab, where one was set to "1424" and the other "1420". Both have now been set to 1424.
If anyone has any suggestions of things I could adjust to make sure the link is reestablished automatically any time it becomes disconnected, I'm all ears.
DFL 210 - firmware v 2.20.01
DFL 800 - firmware v 2.26.00
Thanks.