Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor
Jump to solution

Route-Based VPN (VTI) with Static Route Failover on ClusterXL

Hi Mates,

After configuring two numbered VTIs with static routes and different priorities, when the primary tunnel goes down, traffic does not fail over to the backup tunnel. Any idea please?

0 Kudos
1 Solution

Accepted Solutions
RemoteUser
Advisor

We solved it by repeating the process (recreating the VTI), and we also tested the failover successfully. Everything is now working as expected based on this SK:
https://support.checkpoint.com/results/sk/sk156812

View solution in original post

8 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Are you using DPD and how are the return routes configured?

CCSM R77/R80/ELITE
0 Kudos
RemoteUser
Advisor

I'm using permanent tunnel on the community:
set static-route x.x.x.x/24 nexthop gateway address 169.254.x.x priority 1 on
set static-route x.x.x.x/24 nexthop gateway address 169.254.x.x priority 2 on
set static-route x.x.x.x/24 ping on

0 Kudos
simonemantovani
MVP Gold
MVP Gold

When the first tunnel is down, did you check, in bash, with the command ip route get <ip_of_a_remote_host> what route is used to reach the remote host?

Both remote hop (169.254.x.x) are pingable from the gateway?

0 Kudos
CaseyB
Advisor

My configuration looks something like this:

set static-route 10.x.x.x/24 nexthop gateway address 172.20.x.x priority 1 on
set static-route 10.x.x.x/24 nexthop gateway address 172.20.x.x monitored-ip 192.168.x.x on
set static-route 10.x.x.x/24 nexthop gateway address 172.20.x.x monitored-ip-option fail-any
set static-route 10.x.x.x/24 nexthop gateway logical vpnt10 priority 2 on

Make sure you have a monitored IP set for the primary so it knows when to use the backup.

0 Kudos
simonemantovani
MVP Gold
MVP Gold

Based on this sk https://support.checkpoint.com/results/sk/sk156812

The configuration reported by @RemoteUser should be consistent, eventually, It might be worth checking whether pings are allowed.

0 Kudos
RemoteUser
Advisor

I wonder if this is really enough for failover, or if something else is still needed

0 Kudos
simonemantovani
MVP Gold
MVP Gold

As a first step, I would check if ping is ok, if yes, you can proceed with further checks, for example, by checking which route is used when the first vpn is down.

0 Kudos
RemoteUser
Advisor

We solved it by repeating the process (recreating the VTI), and we also tested the failover successfully. Everything is now working as expected based on this SK:
https://support.checkpoint.com/results/sk/sk156812

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events