static routes remain valid even when ipsec tunnel down?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

static routes remain valid even when ipsec tunnel down?

Not applicable

I discovered that static routes associated with ipsec tunnels that are down remain valid and continue to be redistributed by, in our case, OSPF. This is not the behavior we desire. We'd like the static routes to become invalid and not be redistributed when the corresponding tunnel is down. I had a couple ideas, but trial and error is a difficult proposition with live services, so I'm hoping for some good advice.

  1. We don't have tunnel monitoring on. Would turning it on achieve the desired behavior?
  2. In the static route definitions we set the interface to the appropriate tunnel, but use next hop None. Could this setting be changed to achieve the desired behavior?
  3. Or is there another solution (with the caveat that we prefer to not run, ipsec a routing protocol over the tunnel)?

Thanks for any assistance.

3 REPLIES 3

L4 Transporter

hello

if you don't apply a monitoring on the ipsec tunnel, the tunnel stay in down state until the traffic is route across your tunnel.

you could used the policy base forwarding to redistribute the traffic  to another next hop if your tnnel is down.

to do that create a PBF policy with the next hop your tunnel, and a monitor profile.

and in your virtual router configure the default route to redistribute to the backup next hop

regards

G


Why would you need or want to use a PBF rule if tunnel monitoring is enabled on both ends?

Cyber Elite
Cyber Elite

Hello,

We use OSPF and got rid of almost all of out static routes. We have redundant paths to each outlying office, wan link and internet VPN. so if one goes down, OSPF redistributes the correct path and we are good. 

 

But to quickly answer your questions:

 

1. Path monitoring is what you would want.

https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/networking-features/static...

2. Nope, see number 1

3. OSPF since if its down it will be removed from the routing table.

 

Hope that helps.

  • 5346 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!