Hi all,
I recently setup a new S2S CP-to-CP IPSEC VPN.
Site 1 - 6200 GW cluster (active/standby) - R81.20 JHF 41 (VPN domain 10.10.0.0/16)
Site 2 - SMB 1800 single appliance - R81.10.08 (VPN domain 10.20.0.0/16)
Mgmt - Smart-1 Cloud - R81.20
The VPN has overall been stable except for communication between certain /24 subnets within the VPN domains. For example, overnight I lost communication from 10.20.80.90 to the 10.10.5.0/24 subnet at site 1. All other inter-site traffic was communicating just fine. I checked 'vpn tu tlist' and saw several "narrow" and "eclipsed" entries with "No outbound SA" on a couple of entries.
This is a simple S2S with no overlapping networks and no NAT between the two sites. I've seen some SKs regarding narrowed and eclipsed tunnel related to third-party VPNs, but nothing really for CP-to-CP.
In the community settings, for VPN tunnel sharing, I'm using "one VPN tunnel per subnet pair". Should I just change this "to one tunnel per Gateway pair"?