- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-18-2024 11:42 AM
Hello guys,
Sorry if this topic has been already discussed before but I could not find an answer.
I would like to know why phase 1 is not synchronized between HA pair. Is there a particular reason ?
Thanks
01-19-2024 03:19 PM
Primary reason as far as I'm aware is the same issue that you'll see even on vendors that allow SAs to sync, the sequence number wouldn't stay in sync anyways. So Fortinet as an example you can continue to receive traffic after a failover without a re-key, but as soon as outbound traffic is sent a re-key is required.
PAN and some other vendors have taken the stance that simply configuring it to utilize tunnel monitoring and renegotiating is a better path forward that has consistent behavior.
01-19-2024 02:36 PM
Hi @seag ,
That's an interesting question! I would think the reason why is that the passive firewall is not involved in the IKE negotiation process. Since the primary firewall proposes and establishes phase 1 with the peer, the passive firewall has no phase 1 SA.
01-19-2024 03:19 PM
Primary reason as far as I'm aware is the same issue that you'll see even on vendors that allow SAs to sync, the sequence number wouldn't stay in sync anyways. So Fortinet as an example you can continue to receive traffic after a failover without a re-key, but as soon as outbound traffic is sent a re-key is required.
PAN and some other vendors have taken the stance that simply configuring it to utilize tunnel monitoring and renegotiating is a better path forward that has consistent behavior.
01-23-2024 01:09 AM
Thanks for this explanation... I understand. Imagine the following scenario :
You have an HA Pair with a hundred VPN IPSec tunnels on it. The HA pair is configured in passive mode Gateway.
After a failover, is there a way to prevent the loss of those tunnels without involving peers ?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!