IPSEC tunnel not working post HA failover

Reply
Highlighted
L5 Sessionator

IPSEC tunnel not working post HA failover

Hello Friends,

 

We have Palo Alto firewalls (various models like 3050, 5220 and 3220) which are in HA (active-passive mode).  IPSEC tunnels are working fine when traffic is on active gateway. The issue is, when we failover traffic on passive gateway, internet works fine but my tunnel resources becomes unreachable. When i checked tunnel status on gateway, it shows Phase-2 is up but Phase-1 is down.

 

Then we had to manually initiate traffic from gateway by test vpn commands and after 2-3 mins, tunnel resources becomes reachable. my HA1 and HA2 links are up. Also i see IPSEC SAs getting copied from active to passive. But facing this issues when failover happens. All gateways are running on 9.0.3-h3 but we had this issue on 8.1.x also. Also this issue is not gateway specific, we are facing it on all HA clusters.

 

Is any one faced such issues ??



Mayur Sutare
Highlighted
Community Team Member

Re: IPSEC tunnel not working post HA failover

Hi @SutareMayur ,

 

Did you confgure Tunnel Monitor ?

I'm guessing the tunnel should come back up after the re-key interval but with tunnel monitor it will be faster.

 

Hope this helps,

-Kiwi.

 
Highlighted
L5 Sessionator

Re: IPSEC tunnel not working post HA failover

@kiwi I dont think tunnel monitor will help here. I do not want to failover IPSEC traffic from tunnel one to other. I have only one IPSEC tunnel and traffic should get failover to other firewall when i do firewall HA failover.

 

- Mayur



Mayur Sutare
Highlighted
Community Team Member

Re: IPSEC tunnel not working post HA failover

Highlighted
L5 Sessionator

Re: IPSEC tunnel not working post HA failover

@kiwi,

 

Thanks for your response.

I'll try it out and let you know.

 

Mayur



Mayur Sutare
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!