We have a linksys BEFSX41 at our Main office that is running two vpn's to our branch offices. both of our branch offices have BEFSX41's as well. We have been running fine for about 2 years and then all of a sudden 6 months ago we started having problems. The problems are basically when we go into the router and lets say we open a port at our main office. When we click save and do a soft reboot, it will disconnect both vpn's to our branch offices. Now ok so the vpn is disconnected, just go to the vpn tab and click connect on them both right. Nope that will not work, in order to get the vpns back up and running, the BEFSX41 in the main office must be powered off and turned back on.
So now lets say at Branch1 we want to open a port. So we configure the port and click save to do a soft reset. The VPN between the main office and this branch1 will go down and you cannot connect it. Meanwhile the VPN between the main office and BRANCH2 will stay up. Once again the only way to reconnect the VPN is power off the main office router and power off branch1 router and turn both back on, then the vpn will connect again.
Now also another problem that takes down the VPN's is pcanywhere. At the main office we use pcanywhere to connect to all the remote computers at the two branches. Since this VPN problem started, anytime we connect to a remote computer either at Branch1 or Branch2, we can connect fine do anything we need to do, but when we go to disconnect from the client machine, then the VPN goes down again. Once again the only way to get the VPN back up is to power off the router at the main office.
We have attemped to fix the problem by replacing the router at the main office, which did not help. We also attemped to upgrade to the latest firmware from linksys, did not help. We have played around with MTU settings and still no resolution.
If anyone has ever had this problem before a little help would be much appreciated. We dont know if its hardware/or connection or what. Its mighty puzzling.
Any help would be greatly appreciated.

Dani AI

Generated

As described, two site‑to‑site IPsec tunnels drop after configuration changes or after a remote control session ends, and only a hard power cycle restores them. That pattern points away from simple MTU or single‑port problems and toward one of three things: the router’s IPsec/IKE engine failing to reinitialize after a soft reboot, stale NAT/state handling upstream, or an IPsec rekey/DPD/NAT‑T mismatch that leaves the peers unable to renegotiate. In response to , also note whether the BEFSX41s are the actual VPN endpoints (router‑to‑router) or if a separate VPN server/concentrator is terminating tunnels — troubleshooting steps differ depending on that.

Useful, practical troubleshooting steps (run in a maintenance window):

  1. Capture evidence first — enable any VPN/event logging the BEFSX41 offers or send logs to a syslog host. If router debug is unavailable, run a packet capture on a host behind the WAN interface and filter for UDP 500, UDP 4500 and ESP (protocol 50). Look for IKE errors or rekey failures when the tunnel dies.
  2. Reproduce methodically — perform the port change/save while logging on both ends so the exact failure message is captured. Also repeat the same test with PCAnywhere disabled to isolate whether that app triggers the failure.
  3. Check NAT and WAN behavior — confirm the public IPs are static during the event, and verify no upstream modem/router is doing double‑NAT or blocking UDP 500/4500/ESP. If the ISP/modem is between the BEFSX41 and the internet, power‑cycle or bypass it during tests.
  4. Align IPsec settings — ensure Phase‑1/Phase‑2 lifetimes and NAT‑T/DPD (keepalives) match on both peers. If the BEFSX41 supports DPD or a keepalive option, enable it. Shorten timers temporarily to make problems reproduce faster.
  5. Isolate hardware vs upstream — if logs show the IPsec process hangs, try a factory reset and rebuild the tunnel from scratch on a spare BEFSX41 or a small software VPN (pfSense/strongSwan) to see if the issue follows the line or the device.

If packet captures show IKE rekey or NAT translation failures, share the exact IKE error codes and timestamps when seeking further help. If the device’s IPsec process is crashing or not restarting reliably, a more modern router or dedicated VPN concentrator will provide far more robust behavior.

does your office have a vpn server?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.