Frequently Asked Question

Site to Site VPN Between 213x and 286x
Last Updated 4 hours ago

For site-to-site connectivity between DrayTek Vigor 213x and 286x routers, WireGuard is the recommended VPN protocol. In practical testing, IPsec tunnels between these ranges may establish successfully but still suffer from poor throughput, packet loss, repeated retransmissions and out-of-sequence packets. We tested this with a 2136ax and a 2866 and could reproduce it reliably (or not reliably as in this case). 

These problems are particularly disruptive to stateful protocols such as Microsoft SMB file sharing, authentication and Remote Desktop. Web traffic may appear relatively normal because HTTP-based applications generally recover from retransmissions more gracefully.

Symptoms of the IPsec problem

Typical symptoms include:

  • The IPsec tunnel connects and remains shown as active.
  • Pings are consistent.
  • File shares are slow to open and often fail.
  • Microsoft networking connections stall or disconnect.
  • TCP captures show repeated retransmissions and duplicate acknowledgements.
  • Packets arrive out of sequence.
  • Web browsing appears less severely affected than SMB or other stateful services.

Packet captures taken at either site may confirm that traffic is being lost or reordered inside the tunnel rather than by the application.

The 21xx interface provides fewer IPsec tuning and diagnostic options than the 286x interface. In particular, settings such as TCP MSS adjustment may not be available, making it impractical to resolve the behaviour through conventional IPsec tuning.

Recommended resolution

Replace the IPsec tunnel with a WireGuard site-to-site tunnel rather than spending substantial time adjusting IPsec proposals, MSS values or fragmentation settings.


MTU considerations

WireGuard normally works correctly with an MTU around:

1420

If the WAN service adds extra encapsulation, such as PPPoE, or testing still shows fragmentation, use a lower value such as:

1380

Apply the same tunnel MTU at both ends where the router interface permits it. Start with the firmware default and reduce it only where testing demonstrates an MTU problem.


This website relies on temporary cookies to function, but no personal data is ever stored in the cookies.
OK
Powered by GEN UK CLEAN GREEN ENERGY

Loading ...