Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dunkelmorten
Contributor
Contributor
Jump to solution

sk170857 - How to identify potential segmentations affected by VPN EDPC?

Hello all,

I am preparing for a customer a migration of an SMS running R81.20 to R82.10.

Hence, I have run the "./migrate_server verify -v R82.10" successfully which showed only a single warning for VPN EDPC configuration:

" Verifying the Site to Site VPN Encryption Domain Per Community configuration
The behavior of Encryption Domain Per Community in Site to Site VPN has changed.
Make sure the configuration of VPN traffic selectors on the relevant VPN peers matches the new behavior.
For details, see sk170857."

I was working through the entirely VPN Domains, identified a single overlapping and cleaned it up.

However, the follow-up verification attempt is still showing me this warning and I was trying with no luck figuering out which VPN Domains or even which objects in assigned to VPN Domains could cause this.

Do you have any advice on this?

 

Additionally, as per the sk170857 this should be fixed at all, but still showing this warning.

Is it still necessary to clean this then?

 

BR,
Morten

0 Kudos
1 Solution

Accepted Solutions
Alex-
MVP Silver
MVP Silver

I had it in a few R81.20 to R82 SMS, ignored warnings and all went fine.

Likely a reminder of sort.

View solution in original post

4 Replies
simonemantovani
MVP Diamond
MVP Diamond

Maybe it's only a warning to inform you the changes in vpn behaviour, displayed even if you resolve any conflct.

I'm planning to upgrade also an MDS, and the same warning is displayed, I'll check if it's only a warning displayed even if VPNs are fine.

dunkelmorten
Contributor
Contributor

Yes, I also thought so. Just wanted to ask for confirmation or if there is any chance to close this warning entirely.

I have now also run the verification for R82 with the same result.

This would also prevent running the export successfully unless using the parameter to ignore warnings.

0 Kudos
Alex-
MVP Silver
MVP Silver

I had it in a few R81.20 to R82 SMS, ignored warnings and all went fine.

Likely a reminder of sort.

dunkelmorten
Contributor
Contributor

I would also assume this to be cosmetic thing, since I have worked to all VPN-Domains searching for potential fragmentation of subnets.

Would have been more comfortable if this would only be a warning in case there are matches and providing an overview of what is causing this, saving a lot of time for admins. And in case there are no matches, simply descreasing it to "informational" avoiding concerns for the upgrade process.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events