- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- need to reset tunnel every time when peer end prim...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
need to reset tunnel every time when peer end primary ISP down.
Dear Team,
We have configure site site tunnel between check point, both ends having check point and managed by same management device.
but primary link of peer goes Down, tunnel went down and once we manually reset it start working with secondary link.
Why manual reset required each time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How precisely did you configure it?
ISP Redundancy in use?
What version/JHF?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How precisely did you configure it==> We have cross verify both end all the Phase1 & Phase2 configuration, all re same and it is working . But issue is happen only when Peer end Primary ISP link goes down traffic not shifted towards secondary. Whereas we have configure ISP redundancy and DNS 8.8.8.8 set.
ISP Redundancy in use==> Yes two link Primary and secondary at both end like our end and peer end. and both configured with ISP redundancy.
What version/JHF==>R81 Take 23
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the ISP Redundancy config, have you enabled “Apply settings to VPN traffic” ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes. "Apply Setting to VPN traffic" is enabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Probably a good idea to involve the TAC on this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Also, make sure "keep ike sas" is enabled in global properties...I had seen that applicable for both cp to cp tunnels, as well as cp to 3rd party.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
but on this mangement server mutilple site to site VPNs are working perfectly..For only one specific Site2site only problem..
if i enable keep ike sas,it will not impact other site to site.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had never seen it impact other sites...can you try delete and recreate that site?
