Problem
The CloudVPN router is unable to set up a VPN, Configuration, or Data logging connection.
After several consecutive unsuccessful connection attempts, the connection will be rate limited. Meaning it will still try to connect, but less frequently. If the situation remains unchanged, the router will eventually be blocked. Meaning it will not try to connect again, until it is manually unblocked.
When the connection is checked in the component Cloud connection status, one of the following error messages can be observed:
| Rate Limit Active | Device is blocked |
|
|
This is indicated in the Portal in the Cloud connection status on a device page, in the Fleet Manager overview with an icon, and in the Fleet Manager on an router's info page.
Cause
This can have a wide range of causes, such as a company firewall blocking traffic or a cellular signal that is too weak for a connection.
A firewall is interfering with the connection. In general, this is a company firewall (for wired and Wi-Fi connections) or a firewall at the connection provider (for cellular connections). This can occur with a VPN, Configuration, and Data logging connection. A secure connection is used between the CloudVPN router and the servers in CloudVPN Portal. When a firewall somehow makes a change to this connection, e.g. by opening packets for an SSL inspection, the connection is no longer deemed secure and is disconnected. So, although the CloudVPN router is able to reach the internet and CloudVPN’s servers, setting up the actual connection doesn’t succeed. When there are several consecutive failed connections, rate-limiting occurs. If this continues extensively, connections from the particular CloudVPN router are ultimately blocked altogether. Both a rate limit and a block can be reset in the Cloud connection status component.
Solution
Connection Type:
VPN connection
Try the following first. It may enable your edge gateway to connect without further troubleshooting.
- Try Stealth mode.
- This masks the edge gateway's VPN traffic as regular internet traffic (HTTPS) and may allow your edge gateway to connect.
- Configurable at Fleet Manager > Devices > Click on your device name > Network > VPN > Stealth mode.
- Once enabled, make sure to reset or unblock the error message so your edge gateway will try to connect again. This may take several minutes, depending on the situation.
- If your edge gateway successfully connects, you can continue to use this workaround or proceed with the steps below to find and resolve the root cause. The latter is recommended to find a proper solution instead of using a workaround.
- Stealth mode may have a marginal impact on performance. Though this if often not noticeable in practice.
- If your edge gateway does not connect, turn Stealth mode off and proceed with the steps below.
- Try VPN connection type UDP.
- This makes your edge gateway use a different port (1194) than with TCP (443) and may allow your edge gateway to connect.
- Configurable at Fleet Manager > Devices > Click on your device name > Network > VPN > VPN setup.
- Once enabled, make sure to reset or unblock the error message so your edge gateway will try to connect again. This may take several minutes, depending on the situation.
- If your edge gateway successfully connects, you can continue to use this workaround or proceed with the steps below to find and resolve the root cause. The latter is recommended to find a proper solution instead of using a workaround.
- VPN connection type UDP does not negatively impact the performance or functioning of the edge gateway.
- If your edge gateway does not connect, set VPN connection type to TCP and proceed with the steps below.
- If the VPN connection type is set to UDP, the MTU size may need to be adjusted.
- If the edge gateway is using a cellular connection, try an MTU size of 1350 or 1450. You can change the MTU size at Fleet Manager > Devices > Click on your device name > Network > WAN > Cellular network.
- If the edge gateway is connected via Wi-Fi to a phone hotspot, you cannot configure the MTU size yourself. Instead, please contact us to configure the MTU size for you.
- If the edge gateway is using Wi-Fi or cellular, the signal may be so poor or unstable that the edge gateway cannot establish its connection. Check the signal strength (quality) on the edge gateway's local web interface and improve the signal strength using the tips below if needed.
Configuration / Data logging connection
- If the edge gateway is using Wi-Fi or cellular, the signal may be so poor or unstable that the edge gateway cannot establish its connection. Check the signal strength (quality) on the edge gateway's local web interface and improve the signal strength using the tips below if needed.
- If the edge gateway is using Wired or Wi-Fi, try disabling IPv6.
- Applies to CloudVPN router models only.
- The the router normally falls back to IPv4 when it's unable to connect using IPv6, but in networks that do not have IPv6 fully set up correctly, this may not always be the case. Disabling IPv6 then forces the the router to use IPv4.
- This change cannot be done remotely, only on-site. If this is not possible, but the the router does have a VPN connection (with Stealth mode on or off), please contact us. We can then disable IPv6 for you remotely.
- If the above solution has not resolved the problem, a firewall is intentionally or unintentionally interfering with the edge gateway's connection attempts. This is most common with a wired or Wi-Fi connection, but has occasionally also been observed with cellular connections. Contact the local IT or Internet Service Provider (ISP) and explain the situation using the problem description at the beginning of this article. Also include the following support article, explaining how the edge gateway connects to the our Cloud and listing potential firewall settings that are known to block or interfere: Ports, protocols, and servers used by the router.
Comments
0 comments
Article is closed for comments.