Good Morning Dear Community,
I hope this message finds you well.
I'm reaching out to seek assistance with a problem we've encountered after upgrading our Checkpoint appliances from version R81 to R82.20. We have a Site-to-Site VPN configured between two clusters as follows:
Site1:
- Virtual IP (VIP): 10.7.1.1
- Nodes: 10.7.1.2 and 10.7.1.3
Site2:
- Virtual IP (VIP): 10.1.4.1
- Nodes: 10.1.4.2 and 10.1.4.3
The upgrade process completed successfully on both nodes at Site1. However, post-upgrade, we're experiencing an issue where the VPN is up (IKE phase, IPSec SA, etc.), but traffic is not reaching from Site2 to Site1 and vice versa, specifically to one node.
After the upgrade, node 10.7.1.3 is no longer reachable from Site2, and it cannot reach Site2, while the other node is functioning properly. The cluster is active/standby without any problems.
We're considering factory resetting the problematic node. Has anyone encountered a similar issue?
We've consulted an SK, which suggests that this could be related to having another network device with the same IP as the problematic one. However, in our case, we only have one host object (not a gateway) with the same IP. We don't believe this could be causing such an issue, as everything was functioning properly before the upgrade.
Your insights and experiences would be greatly appreciated.
Thank you for your assistance.