Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec 504 Gateway Time-out when applying changes with a large number of IPSec gateways/tunnels

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 577 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gassyantelope
      last edited by gassyantelope

      Re: IPsec Apply changes time out

      There seems to be a problem when trying to apply IPsec VPN changes when many VPN gateways/tunnels are added. The firewall will throw a 504 gateway time-out error and won't apply the changes on the first attempt. I have to try applying the changes 2-3 times (waiting for a timeout between each attempt) before they will finally apply. It seems to only happen once I surpass ~25 VPNs. Before that, the changes would apply fine.

      There was a thread from last year (which I'm replying to with this thread) where other people were having the same problem. No solution was ever provided in that thread, yet the problem still seems to exist. Is there a solution to solve this problem?

      Thanks

      G 1 Reply Last reply Reply Quote 0
      • G
        glreed735 @gassyantelope
        last edited by

        @gassyantelope Had this very problem with versions 2.5 and below. Version 2.6 had massive improvements to IPSEC handling in the GUI, so 2.6 resolved the issues for me.

        G 1 Reply Last reply Reply Quote 1
        • G
          gassyantelope @glreed735
          last edited by

          @glreed735 Interesting, since I'm already on 2.6 and am having problems. One thing I've noticed, since my original post, is that it seems to primarily happen when adding a new gateway or tunnel. If I edit the settings on an existing one, it applies the changes fine.

          G 1 Reply Last reply Reply Quote 0
          • G
            glreed735 @gassyantelope
            last edited by

            @gassyantelope Our issues was on any add or change to an IPSEC configuration. The Status, IPSEC page was very slow as well, up to a minute to load. Now loads in <1 sec. 2.6.0 definitely fixed all our IPSEC setup and modify 504 errors.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.