Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Martin_S_1
Explorer

VPN Failure after ClusterXL Failover

Hi, 

I was deleting an interface yesterday on our ClusterXL pair of 7000's. The process caused a failover between the two units after I changed the interface from 'Cluster' to 'Private' in SmartConsole. After this the two units failed over. Our site-to-site VPNs we have that terminate on this ClusterXL pair then stopped working. The VPN is a VTI type from what I understand. From the remote side, our third party told us they could see the VPN's were down, but from our side they appeared to be up, SmartView Monitor showed them as up, and we could see Phase1 and Phase 2 SA's using vpn tu. However, what we then noticed was that the BGP peers relationships which run through these VPN tunnels had stopped working. Nothing we did would bring them back up. It was only once we failed the units back over to the original gateway that was active before starting, the BGP peer relationships came back up and VPN's came back up. 

We didn't know why the BGP peer relationships and VPNs failed when we failed over to the other cluster member. Has anyone seen this before or how to troubleshoot this?

0 Kudos
6 Replies
Juan_
Collaborator

Is your router-id a VIP?

0 Kudos
Martin_S_1
Explorer

Yes, the BGP router-id is a VIP. 

0 Kudos
Chris_Atkinson
Employee
Employee

What's the router-id configured as and do you use graceful restart?

0 Kudos
Martin_S_1
Explorer

Hi Chris, how do you normally check if we use graceful restart? Our router-id is configured as one of the cluster IP address VIPs.

 

0 Kudos
Martin_S_1
Explorer

Graceful restart is not enabled. 

0 Kudos
Chris_Atkinson
Employee
Employee

What is the remote end?

Generally it is recommend to enable graceful restart for clustered configurations.

0 Kudos