Good Day everyone.
Have a very intermittent site to site VPN issue. Current environment is 9 locations, connected by private MPLS.
Management is R80.20
(8) clusters are R77.30
(1) cluster is R80.20
I have a mesh VPN community which has 8 locations in it. The 9th location, where management resides is not part of the VPN community.
From time to time, i see a site become unreachable from one or more of the other VPN sites - the fix is to get to that cluster either directly, or via the non-VPN management server, and run vpn tunnelutil and "Delete all IPsec+IKE SAs for ALL peers and users" - that site becomes available immediately.
Any troubleshooting ideas - not knowing when it will happen, or how to trigger it makes setting up anything in advance difficult.
"permanent tunnels" is not turned on - would that setting add value here?
thanks.
dave