Cisco – Some VPNs have 1-5% packet loss

ciscointernetpacket-lossvpn

I am currently in this situation and I'll try to be as specific as I can.
My firewall has 20 VPNs (over the internet) with different vendors. Everything was fine til a month ago.

I usually use ping to monitor the remote networks and some of my VPNs have 1-5% packet loss. The VPN does not go down, but the ping does. The firewall log shows nothing wrong, not any blocked packets everything seems all right. Overall, it is a 0% packet loss / day, but in some intervals it goes to 5% (at about 1pm, where traffic peaks)
Some other VPNs are fine with 100% reply.

What I noticed:

-Most loss occours when we're at peak traffic (again, only for the "damaged" VPNs. The other VPNs are fine)

-From my WAN i have 0% loss with 8.8.8.8 but there's 1-5% packet loss with the remote WANs in question.

-Restarting the firewall stabilizes the situation for about a day, but then everything starts over again.

-The VPN tunnel is UP all the time.

any help from your experience would be truly appreciated

Best Answer

same boat here

what we have determined is carriers are using adavnced boxes (like giant bluecoats) to rate limit udp and esp traffic.

try getting one of these on cisco vpn ezvpn if they are cisco asa 5505's and use ipsec/tcp to the main site with network extension mode. this "chap" has a nice quick write up for you to follow

http://www.jump.net.uk/blog-cisco-easy-vpn-on-asa

the loss stopped when we did ipsec/tcp

but smokeping had 5% loss for weeks.

nasty times, huh?