<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN issue during WAN failover on Quantum Spark (R81.10.17) in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251639#M12827</link>
    <description>&lt;P&gt;Do you have monitoring setup on the interface? We had a similar issue and setup monitoring (ping the upstream DNS servers) and that sorted our issue&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitoring.JPG" style="width: 700px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30808i08BBCC8313B8D877/image-size/large?v=v2&amp;amp;px=999" role="button" title="monitoring.JPG" alt="monitoring.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jun 2025 23:33:50 GMT</pubDate>
    <dc:creator>TJ_Aus</dc:creator>
    <dc:date>2025-06-19T23:33:50Z</dc:date>
    <item>
      <title>VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251630#M12826</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I’d like to ask if anyone has experienced this behavior or if there’s any documentation or workaround available for this scenario.&lt;/P&gt;&lt;P&gt;We currently have a &lt;STRONG&gt;Quantum Spark appliance (R81.10.17)&lt;/STRONG&gt; with &lt;STRONG&gt;two Internet links configured in redundant mode&lt;/STRONG&gt;. The issue occurs when a failover happens:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;When one of the links is disconnected, the other correctly takes over general traffic, but the &lt;STRONG&gt;site-to-site VPN tunnel drops and does not automatically reconnect&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;We confirmed this using the vpn tu command, where the tunnel goes down exactly when the link switches, and &lt;STRONG&gt;it won’t reconnect unless we manually reboot the appliance&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Additionally, &lt;STRONG&gt;even when restoring the second link, the VPN tunnel does not come back up automatically&lt;/STRONG&gt; — it remains down until a manual reboot is performed.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Actions we’ve tried so far:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Updated the appliance to &lt;STRONG&gt;R81.10.17&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Adjusted Load Balancing percentages (tested with &lt;STRONG&gt;50/50 and 60/40&lt;/STRONG&gt;) — same behavior.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Renewed the &lt;STRONG&gt;VPN certificate&lt;/STRONG&gt; (valid for 1 year) — no improvement.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Verified both &lt;STRONG&gt;public IP addresses&lt;/STRONG&gt; for the Internet links, since the gateway object was created with &lt;STRONG&gt;Dynamic IP (DAIP) in SmartConsole&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Questions:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Is there any additional configuration required to force the VPN to automatically reconnect after a WAN failover or when both links are restored?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there a script, workaround, or recommended procedure to restart the VPN tunnels (or VPN services) automatically upon detecting the link change, avoiding a full appliance reboot?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any experience, advice, or documentation you could share would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 17:32:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251630#M12826</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-06-19T17:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251639#M12827</link>
      <description>&lt;P&gt;Do you have monitoring setup on the interface? We had a similar issue and setup monitoring (ping the upstream DNS servers) and that sorted our issue&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitoring.JPG" style="width: 700px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30808i08BBCC8313B8D877/image-size/large?v=v2&amp;amp;px=999" role="button" title="monitoring.JPG" alt="monitoring.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 23:33:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251639#M12827</guid>
      <dc:creator>TJ_Aus</dc:creator>
      <dc:date>2025-06-19T23:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251641#M12828</link>
      <description>&lt;P&gt;Yes, we do have monitoring configured on both WAN interfaces.&amp;nbsp; The issue is that when one link goes down, although general traffic switches correctly to the remaining link, the VPN tunnel drops and doesn't re-establish automatically on the surviving link — unless we&amp;nbsp; reboot the appliance.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Same when both links are back — the tunnel won’t restore on its own.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 23:47:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251641#M12828</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-06-19T23:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251643#M12829</link>
      <description>&lt;P&gt;Make sure these are ebanled.&lt;/P&gt;
&lt;P&gt;VPN community has &lt;STRONG data-start="1346" data-end="1372"&gt;"Keep VPN tunnel open"&lt;/STRONG&gt; enabled&lt;/P&gt;
&lt;P&gt;&lt;STRONG data-start="1389" data-end="1396"&gt;DPD&lt;/STRONG&gt; is enabled under &lt;EM data-start="1414" data-end="1453"&gt;Advanced Settings &amp;gt; Tunnel Management&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 01:36:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251643#M12829</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-20T01:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251683#M12833</link>
      <description>&lt;P&gt;I guess you mean that enabling "Keep VPN tunnel open" is the same as setting Set Permanent Tunnels?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de pantalla 2025-06-20 093604.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30811i468B3E939F7FC4EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Captura de pantalla 2025-06-20 093604.png" alt="Captura de pantalla 2025-06-20 093604.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I looked for the DPD setting under Advanced Settings &amp;gt; Tunnel Management in SmartConsole R81.20, but it’s not there.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 15:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251683#M12833</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-06-20T15:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251685#M12834</link>
      <description>&lt;P&gt;If its set to permanent tunnel option, which it is, thats fine then.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 15:48:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251685#M12834</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-20T15:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251686#M12835</link>
      <description>&lt;P&gt;Question...so when this happens, are there any logs/indication as to why tunnel is down? Does it even show phase 1 or even that does not come up?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 15:59:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251686#M12835</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-20T15:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251690#M12836</link>
      <description>&lt;P&gt;I looked for logs during the test schedule, but only VPN Routing logs appeared.&lt;BR /&gt;It was noticed that sometimes the tunnel would appear like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de pantalla 2025-06-20 104135.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30812i51F526A121BBDC1F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Captura de pantalla 2025-06-20 104135.png" alt="Captura de pantalla 2025-06-20 104135.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 16:44:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251690#M12836</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-06-20T16:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251693#M12837</link>
      <description>&lt;P&gt;What about any of below commands? Just replace ip-addr with the right IP address.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;vpn tu list&lt;BR /&gt;Usage:&lt;BR /&gt;vpn tu list ike&lt;BR /&gt;vpn tu list ipsec&lt;BR /&gt;vpn tu list peer_ike ip-addr&lt;BR /&gt;vpn tu list peer_ipsec ip-addr&lt;BR /&gt;vpn tu list tunnels&lt;BR /&gt;vpn tu tlist&lt;BR /&gt;vpn tu mstats&lt;BR /&gt;vpn tu del ipsec all&lt;BR /&gt;vpn tu del ipsec ip-addr&lt;BR /&gt;vpn tu del ipsec ip-addr username&lt;BR /&gt;vpn tu del ipsec ip-addr from ip-addr to ip-addr&lt;BR /&gt;vpn tu del all&lt;BR /&gt;vpn tu del ip-addr&lt;BR /&gt;vpn tu del ip-addr username&lt;BR /&gt;vpn tu del ip-addr from ip-addr to ip-addr&lt;BR /&gt;vpn tu conn&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 16:46:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251693#M12837</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-20T16:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251695#M12838</link>
      <description>&lt;P&gt;Currently, the VPN tunnel is up and working fine. When I run the commands you shared, everything looks normal.&lt;/P&gt;&lt;P&gt;The issue happens when there’s a failure on one of the WAN links. Specifically, when the primary link —which has the active VPN tunnel— goes down and all traffic switches to the secondary link. At that point, the VPN tunnel does not reconnect automatically.&lt;/P&gt;&lt;P&gt;As far as I understand, with our current configuration, it should automatically re-establish the tunnel, right? At the moment, we’re not experiencing the issue because the primary link is stable, but I’m checking to see if there’s any missing configuration or if it’s something we should escalate to TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 17:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251695#M12838</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-06-20T17:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251697#M12839</link>
      <description>&lt;P&gt;Thats very logical approach to me. Hey, if you are allowed to do remote, I would be happy to check as well.&lt;/P&gt;
&lt;P&gt;Let me know.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 17:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/251697#M12839</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-20T17:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN issue during WAN failover on Quantum Spark (R81.10.17)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/257004#M13226</link>
      <description>&lt;P&gt;Has there been a solution to this?&lt;/P&gt;&lt;P&gt;I'm facing the exact same problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; best regards&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 10:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-issue-during-WAN-failover-on-Quantum-Spark-R81-10-17/m-p/257004#M13226</guid>
      <dc:creator>SimonAmann</dc:creator>
      <dc:date>2025-09-10T10:49:17Z</dc:date>
    </item>
  </channel>
</rss>

