Inbound VPN connections dropping over LTE

neillr

Member
Joined
Jun 13, 2006
Messages
15
Reaction score
0
We have a number of remote systems that connect to our network via a Telkom Mobile LTE link.
They use OpenVPN on port 1194. The systems do remote backups to us via these VPNs, and we use the VPNs for remote support, software updates, etc.
The important fact is that these are INBOUND connections i.e. originating on the remote systems.
This was working perfectly over an ADSL link. Our ADSL line has been problematic recently so we bought an LTE router and some data, and re-configured the remote systems to connect via our LTE link. We are now experiencing the following problems:

1. A remote system will establish its VPN connection to us ok, but as soon as a large (?) data transfer is started from either side (e.g. backup, file transfer, etc) the connection drops. Using traceroute we have seen that this is happening inside the Telkom network. The remote system then remains blocked for some time (+-1hr?) and then re-connects. The remote systems are configured to re-connect immediately, so this "back-off" period is being enforced somewhere on the network path. If we make an outbound VPN connection (from us to the remote system) it works 100% including file transfers etc.
2. It looks like the number of remote systems that can connect at any one time is limited. On the ADSL link we did not see anything like that.

Any help / suggestions would be appreciated.
 
Get a real (at least) workgroup class router, use all what is good on the Huawei - a cellular modem. Disable all routing with DMZ option.
 
Thanks for the replies.
We have looked at the "DoS attack" setting on our router and it is OFF (un-checked).
Is it possible / likely that somewhere in the network path a router / firewall is seeing our traffic as a DoS attack and blocking it?
As I said above, using traceroute we have seen the block is happening inside the Telkom private network.
 
As I said above, using traceroute we have seen the block is happening inside the Telkom private network.
Possible at Telkom. Telkom apn is unrestricted by default, but you are behind one-to-many NAT in order to bypass IPv4 address pool space. Also they might have implemented some anti-DoS meassures to protect consumers from being overcharged, I don't know. Can you force IPv6 on Telkom connection?

Still thinking that professional grade router will handle incoming connection better. Packets are lost at Telkom, but your router is responsible for maintaining connection (keeping translation tables at Telkom routers valid). Huawei B593 is a Home Gateway Router after all.

Question is whether your ADSL router has Ehternet WAN port. If it does, you can easy test new connection with B593 with DMZ using the same router.
 
Last edited:
I never liked B593 due to the number of issues (raw speed yes, but it doesn't make a good router), but I am very pleased with B315, I got it on special from Cell C yesterday. Perhaps you should try it. It supports all SA networks. Model number is B315s-936.
 
Just a thought - but test the VPN on a different port?
 
Top
Sign up to the MyBroadband newsletter
X