I've got a 2 node Cluster sending logs to a remote mgmt server over a VPN VTI.
If I shut down Node B (the one that was brought up first), everything still works (traffic is routing, Cluster is all green. I can push policy, etc) except for the now active Node A sending some packets and log shipping not from itsMGMT IP, but its WAN cluster member interface or sometimes even the local VTI endpoint. Whats also weird is that during this time, I somehow still manage to get logs but they are logged as origined from the FW that is shut off!
Wondering if anyone can shed any light?