Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dphonovation
Collaborator

S2S VTI tunnel problems with vpn accel on

I'm trying to setup a Site2Site tunnel and it seems "half" working.

For now I'll only troubleshoot one side of the connection:

The remote side is 10.40.171.0/26

Local side is: 10.30.171.0/26

 

10.40.171.5 can wget a http page on 10.30.171.62 but cannot ping it.

 

My firewall which has the directional matching for this site2site is allowing all and I can see the ping coming in. And tcpdump on 10.30.171.62 also sees it, but the reply doesn't seem to come back to 10.40.171.5

 

However, if I turn off vpn accel (vpn accel off) - it works. And I'm not sure why.

0 Kudos
5 Replies
the_rock
Legend
Legend

I dont know for sure if regular VPN debugs would help when that feature is off, but TAC case might be worth it to confirm. Maybe do comparison of vpnd.elg file when it works and when it fails.

0 Kudos
PhoneBoy
Admin
Admin

If disabling SecureXL "solves" an issue, the TAC needs to be involved.
However, I suspect the directional match may be the issue (or at least related).

0 Kudos
the_rock
Legend
Legend

He mentioned vpn accel off, but not sure if that changes the situation...

0 Kudos
PhoneBoy
Admin
Admin

Yeah, it's still effectively disabling SecureXL (albeit for VPN traffic).

the_rock
Legend
Legend

Ah, I see what you mean.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events