Community discussions

MUM Europe 2020
 
lz1dsb
Member Candidate
Member Candidate
Topic Author
Posts: 222
Joined: Wed Aug 07, 2013 11:48 am

SSTP tunnel does not detect connection failure

Wed Sep 10, 2014 12:41 pm

I started using SSTP few days ago between three locations. One of them is the SSTP server where all of the tunnels are terminated, the other two - dial in. I've started it with password authentication only for the moment, just to test how it works. Over the tunnels I use OSPF to advertise the networks behind the routers. Hardware: two RB951 and one RB751.
The setup works, but today I notice a strange behavior. My Internet connection at the central site was down for a couple of hours, but then after it recovered - the sstp tunnels didn't come back up again! When I connected to the remote devices, the sstp interfaces were shown as "Running". I had to manually disable/enable the sstp interface to reestablish the connection.
Isn't there a detection mechanism in SSTP that detects link failure? Should I configure something additionally?

On the other hand, I'm also running OVPN tunnels to the same locations in parallel. The OVPN tunnels reestablished without my intervention...
 
User avatar
NAB
Trainer
Trainer
Posts: 503
Joined: Tue Feb 10, 2009 4:08 pm
Location: UK
Contact:

Re: SSTP tunnel does not detect connection failure

Wed Sep 10, 2014 3:23 pm

I have had some very bad experiences using SSTP (tunnels staying up when they shouldn't be and massive packet loss).

I would strongly recommend that you avoid SSTP like the plague if at all possible.
Nicholas Barnes BSc(hons)
Certified Mikrotik Consultant
Certified Mikrotik Trainer

Vitell - Asterisk, Linux and network consultants
Unofficial IRC channel: #routerboard on irc.z.je
 
lz1dsb
Member Candidate
Member Candidate
Topic Author
Posts: 222
Joined: Wed Aug 07, 2013 11:48 am

Re: SSTP tunnel does not detect connection failure

Wed Sep 10, 2014 4:38 pm

I have had some very bad experiences using SSTP (tunnels staying up when they shouldn't be and massive packet loss).

I would strongly recommend that you avoid SSTP like the plague if at all possible.
I think I'm having exactly the same issue here. The SSTP client does not detect that the SSTP server is no longer reachable. It stays up.
From your experience... what would you recommend. Something stable enough...
I have OVPN tunnels in parallel, but I'm having some OSPF routing issues there...
 
User avatar
NAB
Trainer
Trainer
Posts: 503
Joined: Tue Feb 10, 2009 4:08 pm
Location: UK
Contact:

Re: SSTP tunnel does not detect connection failure

Thu Sep 11, 2014 7:05 am

We're running straight L2TP where encryption isn't required and L2TP/IPSec where it is. Works flawlessly.
Nicholas Barnes BSc(hons)
Certified Mikrotik Consultant
Certified Mikrotik Trainer

Vitell - Asterisk, Linux and network consultants
Unofficial IRC channel: #routerboard on irc.z.je
 
MrYan
Member Candidate
Member Candidate
Posts: 109
Joined: Sat Feb 27, 2010 6:13 pm

Re: SSTP tunnel does not detect connection failure

Thu Sep 11, 2014 1:50 pm

Do you have a keepalive-timeout set?
 
lz1dsb
Member Candidate
Member Candidate
Topic Author
Posts: 222
Joined: Wed Aug 07, 2013 11:48 am

Re: SSTP tunnel does not detect connection failure

Thu Sep 11, 2014 5:01 pm

Do you have a keepalive-timeout set?
No, but I noticed that there is such a parameter. I can only see it on the sstp-client though. How should I set it on the server, or this keepalive is just a client function?
 
MrYan
Member Candidate
Member Candidate
Posts: 109
Joined: Sat Feb 27, 2010 6:13 pm

Re: SSTP tunnel does not detect connection failure

Fri Sep 12, 2014 1:00 am

AIUI, once enabled on the client, the server just responds to the relevant keep alive message.

Who is online

Users browsing this forum: MSN [Bot] and 90 guests