<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic after a cluster failover (Cloudguard) the VPN tunnel gets disconnected in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160400#M664</link>
    <description>&lt;P&gt;We have a vpn tunnel between two cluster, one is a pair of OpenServers and the other Cloudguard in Azure.&lt;/P&gt;&lt;P&gt;For the one on OpenServers the gateways are running R80.40. The gateways in Azure we just updated to R81.10.&lt;/P&gt;&lt;P&gt;Since the upgrade when there is a failover in the Cloudguard cluster, the VPN doesn’t work anymore. A quick fix to get it back seems to be re-installing the policy.&lt;/P&gt;&lt;P&gt;Last time we noticed in SmartView monitor the status of the VPN was Up-Phase1. Anyone seen something like this?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2022 18:22:29 GMT</pubDate>
    <dc:creator>flachance</dc:creator>
    <dc:date>2022-10-25T18:22:29Z</dc:date>
    <item>
      <title>after a cluster failover (Cloudguard) the VPN tunnel gets disconnected</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160400#M664</link>
      <description>&lt;P&gt;We have a vpn tunnel between two cluster, one is a pair of OpenServers and the other Cloudguard in Azure.&lt;/P&gt;&lt;P&gt;For the one on OpenServers the gateways are running R80.40. The gateways in Azure we just updated to R81.10.&lt;/P&gt;&lt;P&gt;Since the upgrade when there is a failover in the Cloudguard cluster, the VPN doesn’t work anymore. A quick fix to get it back seems to be re-installing the policy.&lt;/P&gt;&lt;P&gt;Last time we noticed in SmartView monitor the status of the VPN was Up-Phase1. Anyone seen something like this?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 18:22:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160400#M664</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-25T18:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: after a cluster failover (Cloudguard) the VPN tunnel gets disconnected</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160402#M665</link>
      <description>&lt;P&gt;How long does the outage last when you failover? I remember we had similar issues with our CloudGuard cluster on failover, where it would cause up to a 5 minute outage to our on-prem cluster. The failover would eventually complete and the tunnel would re-establish.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you get this issue when your CloudGuard cluster was running another OS version?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2022 20:50:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160402#M665</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-10-25T20:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: after a cluster failover (Cloudguard) the VPN tunnel gets disconnected</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160413#M666</link>
      <description>&lt;P&gt;Depending on the Azure API the failover time should be ~ 2 minutes for VPN scenarios.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Are both clusters under the same management i.e. is either defined as an&amp;nbsp;&lt;SPAN&gt;Interoperable&amp;nbsp;&lt;/SPAN&gt;device object?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In R81 and above we changed the tunnel keep alive to DPD by default for 3rd party devices... refer&amp;nbsp;&lt;SPAN&gt;sk108600 scenario 5.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Also is keep_IKE_SAs configured?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;This property is available under Global Properties -&amp;gt; SmartDashboard Customization -&amp;gt; Advanced Configuration -&amp;gt; VPN advanced properties -&amp;gt; VPN IKE properties.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 00:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160413#M666</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-26T00:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: after a cluster failover (Cloudguard) the VPN tunnel gets disconnected</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160475#M667</link>
      <description>&lt;P&gt;So here are some additional details.&lt;/P&gt;&lt;P&gt;We experienced the issue only after upgrading to R81.10.&lt;/P&gt;&lt;P&gt;The participating gateways are two clusters. One is Checkpoint R80.40 running on OpenServers. The other is Checkpoint R81.10 on Cloudguard (Azure).&lt;/P&gt;&lt;P&gt;They are managed by the same management server running R81.10.&lt;/P&gt;&lt;P&gt;The cluster failover happens fairly quickly but as far as I know the VPN tunnel stays down indefinitely. Until we install the Policy which seems to kick in something and make it works.&lt;/P&gt;&lt;P&gt;Keep_IKE_SAs is configured.&lt;/P&gt;&lt;P&gt;I looked at SK108600 scenario 5, should we use DPD over Tunnel_Test even with all members being CheckPoint?&lt;/P&gt;&lt;P&gt;It’s a Meshed VPN tunnel. With the following properties&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn1.JPG" style="width: 653px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18227iEBBD9C8E6AA36C05/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn1.JPG" alt="vpn1.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn2.JPG" style="width: 611px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18228i6A26F43601A0B346/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn2.JPG" alt="vpn2.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn3.JPG" style="width: 595px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18229i40C0F3F381A16E93/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn3.JPG" alt="vpn3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 14:35:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/after-a-cluster-failover-Cloudguard-the-VPN-tunnel-gets/m-p/160475#M667</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-26T14:35:08Z</dc:date>
    </item>
  </channel>
</rss>

