Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
abihsot__
Advisor

MEP failover speed

Hello,

 

I was looking into using MEP for remote access, however I am struggling to have it running properly. Maybe you will have some ideas and will share your experience.

 

Two gateways (R80.40 latest) covering same encryption domain. Manual MEP mode, with load-sharing. Endpoint VPN client 82.50 for mac, 83.20 for windows.


It all works fine until I want to simulate a failure of one gateway. When connected to gateway abc, I disable it, and VPN client is stuck at reconnecting state and nothing happens. From tcpdump I see it sends udp/4500 and tcp/443 to gateway abc, but never tries the other one.  I stop reconnection and try establishing new connection and with some delay connection succeeds. Tried sk115996 - no help.

 

Uploading trac file from the gateway just in case.

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

If you notice in sk115996, it says the default failover timer is 2 minutes.
Even with the configuration specified in sk115996, the minimum failover time you can configure is 1 minute.

0 Kudos
abihsot__
Advisor

Yes, I am aware of that. I waited at least 10 minutes and nothing happened, hence the post. I was checking with tcpdump on the client and during reconnect not a single connection was sent to the other node. Something is wrong with the config and I can't figure it out. Anyway, TAC case registered too.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events