Oracle Cloud Infrastructure Documentation

IPSec VPN Troubleshooting

This topic covers troubleshooting techniques for an IPSec VPN that has issues.

Some of the troubleshooting techniques assume that you are a network engineer with access to your CPE's configuration.

General Issues

IPSec tunnel is DOWN
IPSec tunnel is UP, but no traffic is passing through
IPSec tunnel is UP, but traffic is passing in only one direction

For an IPSec VPN with a Policy-Based Configuration

IPSec tunnel is DOWN
IPSec tunnel is UP but keeps flapping
IPSec tunnel is UP but traffic is unsteady

Redundant Connections

Keep in mind these important notes:

  • FastConnect uses BGP dynamic routing. IPSec connections use static routing and do not support BGP.
  • You can use two IPSec connections for redundancy. If both IPSec connections have only a default static route (0.0.0.0/0) configured, traffic will route to either of those connections because Oracle uses asymmetric routing. If you want one IPSec connection as primary and another one as backup, configure more-specific static routes for the primary connection and less-specific routes (or the default route of 0.0.0.0/0) on the backup connection.
IPSec and FastConnect are both set up, but traffic is only passing through IPSec
Two on-premises data centers each have an IPSec connection to Oracle, but only one is passing traffic