<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route-based VPN failover issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155447#M26488</link>
    <description>&lt;P&gt;Thanks, responded : - )&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 16:47:52 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-08-22T16:47:52Z</dc:date>
    <item>
      <title>Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155348#M26416</link>
      <description>&lt;P&gt;Good evening,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set up a route-based VPN between our on-prem cluster to Azure Network Gateway. We experience a disruption to the VPN tunnel when failing over between the cluster members.&amp;nbsp; As soon as the tunnel is reset by the remote peer, the tunnel is immediately re-established. The VTI is configured identically on both gateways, as is the routing. I can see in the gateway object under Network Management that the VTI is configured with a VIP, with the correct addresses for both cluster members. When running vpn tu tlist on both members, I can see the SAs are synched.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any additional configuration required for full redundancy on VTIs/route based VPNs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R80.40 T161&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 19:31:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155348#M26416</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-08-21T19:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155350#M26418</link>
      <description>&lt;P&gt;I cant recall exact setting now in web UI, but make sure in VTI settings that peer name (I believe is option when configuring VTI) is EXACTLY the same as what you gave it for interoperable object for both members, because if not, it will never work properly when there is a failover.&lt;/P&gt;
&lt;P&gt;Also, static route to Azure side would use default gateway that is IP on Azure side net thats not in use. So say if your master has vti ip 169.254.10.55 and other one is 169.254.10.56, then vip can be say .57 and default gateway to reach azure can be say .60, as long as its not used anywhere on Azure side.&lt;/P&gt;
&lt;P&gt;Message me offline if you need help, I can check this for customer we did it between on prem and cloud for few tunnels and works fine with failover and also its all route based with VTIs. Also, MAKE SURE that default gateway I was referring to is the SAME ip address as what you have when you edit topology for VTI and then under remote address field under vpn tunnel tab (2nd from the top on the left).&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 23:13:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155350#M26418</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-21T23:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155352#M26420</link>
      <description>&lt;P&gt;If using dynamic routing (BGP) is graceful restart configured?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 23:13:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155352#M26420</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-21T23:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155368#M26421</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;. We're not using any dynamic routing, just two static routes.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 06:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155368#M26421</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-08-22T06:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155369#M26422</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;, I'll send you a PM.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 06:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155369#M26422</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-08-22T06:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155447#M26488</link>
      <description>&lt;P&gt;Thanks, responded : - )&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 16:47:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155447#M26488</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-22T16:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155464#M26493</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64803"&gt;@AaronCP&lt;/a&gt;&amp;nbsp;and myself did remote session and we are pretty sure that reason why this fails is due to routing. We went through the settings on VTI in web UI and saw that remote peer seemed to be wrong, which is what was used for static router as well as default gateway. Once thats fixed, please let us know if that works &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 20:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155464#M26493</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-22T20:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155534#M26513</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing the remote peer as you suggested has resolved the issue! When we failover to the standby member, the VPN tunnel stays up!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help with this!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 18:36:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155534#M26513</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-08-23T18:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN failover issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155553#M26519</link>
      <description>&lt;P&gt;Next time, I have a fee, 100 euros, I take British pounds as well ; - ). Just kidding, it was my pleasure to help you!!&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 22:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-failover-issue/m-p/155553#M26519</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-23T22:51:16Z</dc:date>
    </item>
  </channel>
</rss>

