- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: S2S VTI tunnel problems with vpn accel on
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
S2S VTI tunnel problems with vpn accel on
I'm trying to setup a Site2Site tunnel and it seems "half" working.
For now I'll only troubleshoot one side of the connection:
The remote side is 10.40.171.0/26
Local side is: 10.30.171.0/26
10.40.171.5 can wget a http page on 10.30.171.62 but cannot ping it.
My firewall which has the directional matching for this site2site is allowing all and I can see the ping coming in. And tcpdump on 10.30.171.62 also sees it, but the reply doesn't seem to come back to 10.40.171.5
However, if I turn off vpn accel (vpn accel off) - it works. And I'm not sure why.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I dont know for sure if regular VPN debugs would help when that feature is off, but TAC case might be worth it to confirm. Maybe do comparison of vpnd.elg file when it works and when it fails.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If disabling SecureXL "solves" an issue, the TAC needs to be involved.
However, I suspect the directional match may be the issue (or at least related).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
He mentioned vpn accel off, but not sure if that changes the situation...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yeah, it's still effectively disabling SecureXL (albeit for VPN traffic).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, I see what you mean.
