<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Failure after ClusterXL Failover in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141887#M21943</link>
    <description>&lt;P&gt;What is the remote end?&lt;/P&gt;
&lt;P&gt;Generally it is recommend to enable graceful restart for clustered configurations.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Feb 2022 11:42:26 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-02-18T11:42:26Z</dc:date>
    <item>
      <title>VPN Failure after ClusterXL Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141866#M21935</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was deleting an interface yesterday on our ClusterXL pair of 7000's. The process caused a failover between the two units after I changed the interface from 'Cluster' to 'Private' in SmartConsole. After this the two units failed over. Our site-to-site VPNs we have that terminate on this ClusterXL pair then stopped working. The VPN is a VTI type from what I understand.&amp;nbsp;From the remote side, our third party told us they could see the VPN's were down, but from our side they appeared to be up, SmartView Monitor showed them as up, and we could see Phase1 and Phase 2 SA's using vpn tu. However, what we then noticed was that the BGP peers relationships which run through these VPN tunnels had stopped working. Nothing we did would bring them back up. It was only once we failed the units back over to the original gateway that was active before starting, the BGP peer relationships came back up and VPN's came back up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We didn't know why the BGP peer relationships and VPNs failed when we failed over to the other cluster member. Has anyone seen this before or how to troubleshoot this?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 10:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141866#M21935</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-18T10:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Failure after ClusterXL Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141868#M21936</link>
      <description>&lt;P&gt;Is your router-id a VIP?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 10:17:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141868#M21936</guid>
      <dc:creator>Juan_</dc:creator>
      <dc:date>2022-02-18T10:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Failure after ClusterXL Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141869#M21937</link>
      <description>&lt;P&gt;What's the router-id configured as and do you use graceful restart?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 10:27:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141869#M21937</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-18T10:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Failure after ClusterXL Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141871#M21939</link>
      <description>&lt;P&gt;Yes, the BGP router-id is a VIP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 10:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141871#M21939</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-18T10:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Failure after ClusterXL Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141876#M21941</link>
      <description>&lt;P&gt;Hi Chris, how do you normally check if we use graceful restart? Our router-id is configured as one of the cluster IP address VIPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 10:42:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141876#M21941</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-18T10:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Failure after ClusterXL Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141883#M21942</link>
      <description>&lt;P&gt;Graceful restart is not enabled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 11:10:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141883#M21942</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-18T11:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Failure after ClusterXL Failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141887#M21943</link>
      <description>&lt;P&gt;What is the remote end?&lt;/P&gt;
&lt;P&gt;Generally it is recommend to enable graceful restart for clustered configurations.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 11:42:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Failure-after-ClusterXL-Failover/m-p/141887#M21943</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-18T11:42:26Z</dc:date>
    </item>
  </channel>
</rss>

