Retransmitting in response to duplicate packet

Error messages like "retransmitting in response to duplicate packet; ..." in DEFENDO's IPSec log can be caused by fragmented packets.
IP packets which exceed the maximum size accepted between two hops in a network have to be split into multiple smaller packets. This is called fragmentation. Although this is neither unusual nor something bad, some routers in the Internet are configured in a way which will break fragmented connections. Either fragmented packets are silently discarded or the ICMP notification asking the sender to transmit smaller packets is dropped.
As VPN has to extend the original data packet, these routers will cause trouble. The encrypted packet is usually too large to be transmitted without fragmentation.
To avoid such problems, DEFENDO supports IKE fragmentation. If the peer supports this option, too, the connection should be established without problem.

Secure

DEFENDO forces a collection of best-of-breed security modules like firewall, VPN, proxies, virus scanner and anti spam system to interact for one purpose:
To be protected from all online threats and unwanted contents like malicious code, spam and hacker attacks.

Flexible

Each IT scenario is different. The DEFENDO product family will adapt precisely to your demands.
DEFENDO applies for simple Internet connections of small companies, for headquarters / branch office WANs, as well as for complex multi-tiered firewall systems.

More good reasons

  • No backdoors
  • More than 20 years of Internet security experience
  • Award-winning product
  • Support by our development engineers
  • Reseller loyalty
  • Made in Germany