Using a VyOS AWS AMI I noticed the bellow error message when one IPSec tunnel carries around 25Mbps:
ERROR: "peer-x.x.x.x-tunnel-1" #328: sendto on eth0 to x.x.x.x:500 failed in ISAKMP notify. Errno 105: No buffer space available
I moved the traffic to the secondary VyOS router (same instance size as the primary) and the same error message appeared. The actual symptoms are packet loss and increased latency. The instance CPU is sitting at around 30%. Any thoughts on what type of limit is being hit here and how to get around it (configuration change etc.)?
Hi @Dmitry
I have not been able to reproduce the specific scenario. I do however think that that this issue was caused by a bug in the code on my side that was establishing millions of connections incorrectly though our VyOS routers. I think this might have caused too much load on conntrack. I have subsequently disabled conntrack completely as I don’t need it (I just had one scr NAT configured that added conntrack in iptables).
If this resurfaces, I will let you know but so far, so good.