- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: CloudGuard (ESXi) ClusxterXL Switch IPSec VPN ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CloudGuard (ESXi) ClusxterXL Switch IPSec VPN doesn't work
Hello,
We deployed CloudGuard (ESXi) ClusterXL. Now 6 site connected with IPSec VPN.
When we swtiched ClusterXL some site IPsec VPN work well, but other site doesn't work.
CloudGuard ClsuterXL only has a private IP, but is in a NAT environment for IPSec VPN.
In this case, what should I check?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which version & JHF level?
Are the remote sites also CP gateways or no, any of them DAIP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
All sites are CP Gateway (R81.20 Take 53) and use static IP only.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Make sure your inbound NAT rule(s) are pointing to the cluster VIP and not the IP address of the primary VM. Check the logs for any connection failure messages. TCPdump to make sure the connection attempts are getting to the gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When I checked each cluster member, Firewall1 (normal) is try connect IPSec VPN with own IP.
But Firewall2 (abnormal) is try to connect IPSec VPN with VIP.
I guess both members should try to connect as VIP, but it doesn't work that way.