For the mom who gives us everything - Mother's Day gifts that connects us.
Need help with your equipment?
calgar's profile

Contributor

 • 

2 Messages

Thursday, January 24th, 2013 10:16 PM

IPSEC tunnel not working after recent Outage

Hi to all:

 

I'm new to the forum and I'm not sure if this is the right area (lots of options) but here it goes.

After the recent Uverse outage my ANIRA (AT&T Managed Service) IPSEC tunnel stopped working.. I opened a ticket with the service and didn't find anything wrong with the setup.  The tech suggested to move the VPN box to another ISP and so I tested with AT&T DSL Service and other providers and it works flawlessly.. as soon as I bring it back to Uverse the VPN connection is never established

 

The error I'm receiving on my Uverse Router is src=xxx.xxx.xxx.xxx dst=xxx.xxx.xxx.xxx ipprot=1 icmp_type=3 icmp_code=3 ICMP Dest Unreachable, session terminated... Digging on ICMP Type 3 code 3, it states that it is a  Port unreachable error. Sent when the designated transport protocol is unable to demultiplex the datagram but has no protocol mechanism to inform the sender.

 

I'm just wondering if traffic has been rerouted through other devices that might be blocking ports that support IPSEC?  

 

Any ideas/suggestions?

 

Thanks!

 

Carlos

Accepted Solution

Official Solution

Expert

 • 

9.4K Messages

11 years ago

In all likelihood, your connection probably has the small 576 byte MTU assigned to it, which will probably break any IPSec VPN. See the following thread for the details:

http://forums.att.com/t5/Features-and-How-To/MTU-change-after-1-21-outage/td-p/3408917

Contributor

 • 

2 Messages

11 years ago

You were definetely right.. my MTU was lowered... I just went to the RG and ask to refresh the Broadband connection,,, MTU was changed to 1500 and VPN is up now.

 

Thanks again for your guidance.

 

Best regards

 

Carlos

Not finding what you're looking for?
New to AT&T Community?
New to the AT&T Community? Start by visiting the Community How-To.
New to the AT&T Community?
Visit the Community How-To.