Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SoRee
Participant

CloudGuard (ESXi) ClusxterXL Switch IPSec VPN doesn't work

Hello,

 

We deployed CloudGuard (ESXi) ClusterXL. Now 6 site connected with IPSec VPN.

When we swtiched ClusterXL some site IPsec VPN work well, but other site doesn't work.

CloudGuard ClsuterXL only has a private IP, but is in a NAT environment for IPSec VPN.

In this case, what should I check?

 

0 Kudos
4 Replies
Chris_Atkinson
Employee Employee
Employee

Which version & JHF level?

Are the remote sites also CP gateways or no, any of them DAIP?

CCSM R77/R80/ELITE
0 Kudos
SoRee
Participant

All sites are CP Gateway (R81.20 Take 53) and use static IP only.

0 Kudos
emmap
Employee
Employee

Make sure your inbound NAT rule(s) are pointing to the cluster VIP and not the IP address of the primary VM. Check the logs for any connection failure messages. TCPdump to make sure the connection attempts are getting to the gateway. 

0 Kudos
SoRee
Participant

When I checked each cluster member, Firewall1 (normal) is try connect IPSec VPN with own IP.
But Firewall2 (abnormal) is try to connect IPSec VPN with VIP.
I guess both members should try to connect as VIP, but it doesn't work that way.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.