Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Kentrox Q2300 and 5410 SWIP drops VPN tunnel?

Status
Not open for further replies.

ame540

Technical User
Sep 14, 2004
229
US
Hello!

I did some searching and am pleased to have seen that at least a couple of other people have posted about using a Kentrox Q2300 with some Avaya VPN phones on Tek-tips. We have an interesting problem.

Our outsourced VOIP company set us up with a Kentrox Q2300 to manage a VPN tunnel to a Avaya 5410SWIP with a built in VPN client. This phone apparently can connect just fine back to our IP office, this is an executive of the company that wanted an extension in his home office.

Now, we have an employee that is going to be telecommuting. Management decides that we should use the same setup as the executive. We have another 5410SWIP lying around, i configure it (with what i think are the correct settings, similar to the other phone) and take it home to test.

It is able to connect back to the Kentrox, and establish a VPN connection however it does not last. I get all the phone menus on the phone softkeys, but after literally 60 seconds, the tunnel drops and the phone locks up as if its connected to the call still, but there is no voice traffic. The timer on the phone actually continues to increment. Only after a long period of time does the phone finally give up. I think sometimes it says "discover" on the screen.

Is there any particular setting i should start looking at to try and figure out why the VPN tunnels don't stay connected once this new phone is added?

The VOIP extension in IPO manager is configured as follows:

- IP address: 0.0.0.0
- Compression Mode: G.729(a) 8K CS-ACELP
- TDM->IP Gain: Default
- IP ->TDM Gain: Default
- H450 Support: None
- Be sure “VPN Phone Allowed” IS CHECKED
- Be sure “Allow Direct Media Path” is UNCHECKED
 
Anyone using a Kentrox endpoint for VPN phones?
 
did you pick the same virtual IP in the 5610 VPN phone as the executive? This would cause problems, the virtual IP should be unique for each VPN phone.

Also, u could try setting the encapsulation method from 4500-4500 to disable on the VPN phone.
 
I was able to figure this out. No the IP's were unique, however the IKE ID's were the same.

This caused the Kentrox to try and assign one of the phones BOTH ip addresses, and depending on who built the tunnel first, they would get connectivity until the other one tried and booted it off.

Once the IKE ID's were unique, each was assigned its own dynamic gateway and everything has remained stable.

:)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top