<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN redundancy issue from onprem cluster to Harmony sase in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255543#M1181</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;How many ISPs do you have on the on prem cluster?&lt;/P&gt;
&lt;P&gt;If you have at least two, you can set one tunnel from each ISP.&lt;/P&gt;
&lt;P&gt;Configure Redundant tunnels in P81 side - for each tunnel configure different on-prem interface public IP.&lt;/P&gt;
&lt;P&gt;On the CP side configure two interoperable device as center in community.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two vti's - one per interoperable device.&lt;/P&gt;
&lt;P&gt;Set static route such that each sase gw vpn peer IP goes out via the corresponding ISP (as what P81 expect)&lt;/P&gt;
&lt;P&gt;Notice that if sase is able to initiate tunnel to on prem (inbound is working) it will work. But if not and only your on prem can initiate tunnel to the sase then the ID the GW send during neg must be accurate as configured in sase tunnel configuration under remote ID. or sase will reject it. (Can be seen in vpn debug. Note GAIA currently can't send different ID per interface)&lt;/P&gt;
&lt;P&gt;Make sure both tunnels to both sase GWs are UP (vpn tu tlist)&lt;/P&gt;
&lt;P&gt;Configure bgp vs each VTI and make sure your advertise your relevant networks to sase peers and accept routes from it.&lt;/P&gt;
&lt;P&gt;Verify bgp established: show bgp peers&lt;/P&gt;
&lt;P&gt;Create routemap or inbound route filters+route redistribution to accept/advertize routes.&lt;/P&gt;
&lt;P&gt;Verify routes learned and advertized.&lt;/P&gt;
&lt;P&gt;Let me know on which stage you get issue.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Aug 2025 13:53:06 GMT</pubDate>
    <dc:creator>AmirArama</dc:creator>
    <dc:date>2025-08-20T13:53:06Z</dc:date>
    <item>
      <title>VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255422#M1176</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;We already do have case with escalation TAC team on this, but figured would also post it here to see if anyone might have seen this sort of issue before. Essentially, here is the breakdown to make long story short:&lt;/P&gt;
&lt;P&gt;-onprem cluster, 6200 appliances, R81.20 jumbo 99, mgmt is Smart-1 cloud, R82&lt;/P&gt;
&lt;P&gt;-2 POPs involved , lets call them POP 2 and POP 3&lt;/P&gt;
&lt;P&gt;-if users randomly get connected to Pop 3, no issues at all, but if it goes to Pop 2, nothing works.&lt;/P&gt;
&lt;P&gt;Senior P81 guy checked everything, verified no issues on their end. They checked the routing, logs, all checked out fine.&lt;/P&gt;
&lt;P&gt;Drop on CP side shows according to policy, packet should not have been decrypoted. Funny enough, my colleague and I initially came up with an idea (before that error happened), for redundancy, to have 2 interoperable objects set as center gateways and onprem cluster as satellite, that worked for maybe a week, but then issue happened.&lt;/P&gt;
&lt;P&gt;TAC said was fine to have empty group as enc. domains for all 3 entities (if you will), but no joy. Below&amp;nbsp; is one thing thats interesting that comes up, when they did debug, which is super odd, since they even verified VTIs are configured properly, no issues.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&lt;SPAN&gt;@;166106316.42204434;14Aug2025 14:37:41.021523;[vs_0];[tid_1];[fw4_1]&lt;/SPAN&gt;&lt;SPAN&gt;;get_peer_vpn_if_mapping_cpip: no vpn interface for peer x.x.x.x;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&lt;SPAN&gt;@;166106316.42204435;14Aug2025 14:37:41.021525;[vs_0];[tid_1];[fw4_1];dynamic_vpn_ip: dir 0, 10.255.0.34:1 -&amp;gt; 192.168.32.50:0 IPP 1 Chain: 0x7f77a4531bc8, IP: 192.168.32.50 Decr_Peer: x.x.x.x Position: 18 ;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&lt;SPAN&gt;@;166106316.42204436;14Aug2025 14:37:41.021526;[vs_0];[tid_1];[fw4_1];connection_should_be_tagged: connection should have been tagged.;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&lt;SPAN&gt;@;166106316.42204437;14Aug2025 14:37:41.021527;[vs_0];[tid_1];[fw4_1];fwconn_get_app_opaque: connection not found;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&lt;SPAN&gt;For what is worth, all tunnels show as permanent and UP and doing a reset of the tunnel sadly does not help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&lt;SPAN&gt;I am grateful for any insights/suggestions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.25pt; color: #2f2f2f;"&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 17:33:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255422#M1176</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-19T17:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255449#M1177</link>
      <description>&lt;P&gt;When you're doing VTIs, empty encryption domains are normal.&lt;BR /&gt;That said, it's hard to say which "Check Point" end may be the issue here.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 19:28:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255449#M1177</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-19T19:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255450#M1178</link>
      <description>&lt;P&gt;I dont know, very strange problem...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 19:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255450#M1178</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-19T19:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255471#M1179</link>
      <description>&lt;P&gt;So if this is VTIs how is all the supporting routing configured is there a diagram explaining it?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 00:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255471#M1179</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-08-20T00:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255472#M1180</link>
      <description>&lt;P&gt;Hey Chris,&lt;/P&gt;
&lt;P&gt;My colleague might have a diagram, but odd thing is that though vti's are configured exact same way for both tunnels, one never seems to work. Lets see what escalation team says. I wish sd wan was supported with sase, this would never be an issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 01:09:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255472#M1180</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-20T01:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255543#M1181</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;How many ISPs do you have on the on prem cluster?&lt;/P&gt;
&lt;P&gt;If you have at least two, you can set one tunnel from each ISP.&lt;/P&gt;
&lt;P&gt;Configure Redundant tunnels in P81 side - for each tunnel configure different on-prem interface public IP.&lt;/P&gt;
&lt;P&gt;On the CP side configure two interoperable device as center in community.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two vti's - one per interoperable device.&lt;/P&gt;
&lt;P&gt;Set static route such that each sase gw vpn peer IP goes out via the corresponding ISP (as what P81 expect)&lt;/P&gt;
&lt;P&gt;Notice that if sase is able to initiate tunnel to on prem (inbound is working) it will work. But if not and only your on prem can initiate tunnel to the sase then the ID the GW send during neg must be accurate as configured in sase tunnel configuration under remote ID. or sase will reject it. (Can be seen in vpn debug. Note GAIA currently can't send different ID per interface)&lt;/P&gt;
&lt;P&gt;Make sure both tunnels to both sase GWs are UP (vpn tu tlist)&lt;/P&gt;
&lt;P&gt;Configure bgp vs each VTI and make sure your advertise your relevant networks to sase peers and accept routes from it.&lt;/P&gt;
&lt;P&gt;Verify bgp established: show bgp peers&lt;/P&gt;
&lt;P&gt;Create routemap or inbound route filters+route redistribution to accept/advertize routes.&lt;/P&gt;
&lt;P&gt;Verify routes learned and advertized.&lt;/P&gt;
&lt;P&gt;Let me know on which stage you get issue.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 13:53:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255543#M1181</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2025-08-20T13:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255545#M1182</link>
      <description>&lt;P&gt;Hey Amir,&lt;/P&gt;
&lt;P&gt;Thanks for all that, appreciated! Yes, we verified all the points, so now Im waiting for Escalation guy from TAC to provide next details based on the debugs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But again, here is what baffles me personally, why would it show this when we verified (with both P81 and CP TAC) that VTIs are set correctly.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;@;166106316.42204434;14Aug2025 14:37:41.021523;[vs_0];[tid_1];[fw4_1]&lt;/SPAN&gt;&lt;SPAN&gt;;get_peer_vpn_if_mapping_cpip: no vpn interface for peer x.x.x.x;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;@;166106316.42204435;14Aug2025 14:37:41.021525;[vs_0];[tid_1];[fw4_1];dynamic_vpn_ip: dir 0, 10.255.0.34:1 -&amp;gt; 192.168.32.50:0 IPP 1 Chain: 0x7f77a4531bc8, IP: 192.168.32.50 Decr_Peer: x.x.x.x Position: 18 ;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;@;166106316.42204436;14Aug2025 14:37:41.021526;[vs_0];[tid_1];[fw4_1];connection_should_be_tagged: connection should have been tagged.;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;@;166106316.42204437;14Aug2025 14:37:41.021527;[vs_0];[tid_1];[fw4_1];fwconn_get_app_opaque: connection not found;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 13:59:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255545#M1182</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-20T13:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255546#M1183</link>
      <description>&lt;P&gt;I don't know.&lt;/P&gt;
&lt;P&gt;I can't comment on few debug prints without the full kernel debug. as well as without whole context, configurations, status, and other outputs.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 14:07:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255546#M1183</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2025-08-20T14:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255547#M1184</link>
      <description>&lt;P&gt;Fair enough. I sent you the case number via DM, if you are able to check, no rush.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 14:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255547#M1184</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-20T14:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255580#M1185</link>
      <description>&lt;P&gt;I had good conversation with one of customer's SE and he told me escalation team is 100% sure based on all they had discovered this is onprem cluster issue and not SASE side. They engaged R&amp;amp;D on it, so once they get back to me, will update on how this is all sorted out. It might take some time, but Im confident it will get solved.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 18:51:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255580#M1185</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-20T18:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy issue from onprem cluster to Harmony sase</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255934#M1186</link>
      <description>&lt;P&gt;Quick update..esc. engineer asked me if I can recreate affected VTI and try that. I was more than willing to, but since even after deleting the interface from route it was part of, kept complaining, so I simply ended up disabling/re-enabling VTI on both fws and bam, ping started working right away on affected POP.&lt;/P&gt;
&lt;P&gt;I asked the client to test, but its amazing news, lets see what they say.&lt;/P&gt;
&lt;P&gt;24 hours later, looks good. Its still bit confusing why this worked, makes me wonder if it could be a bug or something else, but as long as it works, good enough for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 14:23:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-redundancy-issue-from-onprem-cluster-to-Harmony-sase/m-p/255934#M1186</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-26T14:23:23Z</dc:date>
    </item>
  </channel>
</rss>

