Our VPN tunnels changed to down on the 28th of Jan with no changes from our side

0

Hi All,

We have a site to site VPN connection which was working till the 28th of Jan. We have not made any changes and the client claims the same. There are no logs streams created in CloudWatch. We've gone through - https://aws.amazon.com/premiumsupport/knowledge-center/vpn-tunnel-troubleshooting/ https://aws.amazon.com/premiumsupport/knowledge-center/vpn-tunnel-phase-2-ipsec/ And https://forums.aws.amazon.com/thread.jspa?threadID=217841

However since we can't understand which phase has failed exactly we can't get a fix, could somebody help?

已提問 2 年前檢視次數 485 次
3 個答案
1
已接受的答案

Hello, I believe as recommended, opening a support case would be the best bet. Even Developer Plan has Email support. In any case, I would recommend checking the CGW side logs. Since Site to Site VPN also has aCustomer Gateway which is on the On-Premise device. Also check for the timestamp when the tunnels went down exactly so that you can have the debug logs and check further. Also, Was the VPN ever working ? AWS VPN has 2 phases- It will be better to proceed with the troubleshooting steps on what phase has caused an issue. Phase-1: https://aws.amazon.com/premiumsupport/knowledge-center/vpn-tunnel-phase-1-ike/ Phase-2: https://aws.amazon.com/premiumsupport/knowledge-center/vpn-tunnel-phase-2-ipsec/

Another suggestion would be to check the troubleshooting from the CGW side by contacting the CGW side Vendor. Hope this helps.

profile pictureAWS
支援工程師
已回答 2 年前
  • I would also recommend to check for any PHD which is Dashboard notifications received during the same time with respect to the VPN.

  • The fix was to create a DNAT config in the client vendor's network. I was trying to find logging for all VPN services but couldn't get anything. Could you guide me on where to find logs for the same?

0

I'd recommend that you create a support case for this - as you've been through the steps documented we (here on re:Post) don't have access to live systems in your account; but the support team can help you with that.

profile pictureAWS
專家
已回答 2 年前
  • We have a basic account, so unfortunately that isn't possible either. Is there any way to understand what is going wrong with the connection? Or would deleting and recreating the VPN be a better bet?

0

Hello. AWS VPN logs are proprietary to AWS Internal VPN teams only and are not customer facing. You will have to Premium Support or contact the the accounts team to help you get the logs. However, they are not public facing and are not visible to any AWS customers despite the Support Plan level.

You can use Cloud watch logs to check the tunnel Status and Tunnel Data In/Out as per the link mentioned on the public facing document. https://docs.aws.amazon.com/vpn/latest/s2svpn/monitoring-cloudwatch-vpn.html

profile pictureAWS
支援工程師
已回答 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南