Hey,
We have a remove site with an XG firewall that simply provides remote SSL and internet access to the site. In order to reach our corporate network, we build 3 VPNs, one to each data center with it's own address space.
When the VPNs are active, the entire site experiences extreme slowness and the CPU reads from 60 - 80% utilisation. As soon as I disable the VPN tunnels the site is back to normal. I tried disabling one by one to see if it's just one of the tunnels but all 3 need to be disabled in order for the issue to go away. The site experiences 90% packet loss with the VPNs on.
The configuration is very simple. We have 1 local subnet for the site and a few remote subnets at the other end. I tried the security rules with VPN as the destination zone but that didnt help. I also let the firewall generate automatic rules, same issue. The CPU continues to spike no matter how I write the access rules. Sometimes, it will also send traffic not over the VPN but over the internet link. It's almost like the firewall gets confused about routing and either drops traffic, loops it, or send its out the internet link.
We are running version XG230 (SFOS 18.5.2 MR-2-Build380). Could this be a bug or is my config wrong. I have another firewall like this on another site and it works perfectly fine with the same IPSec config.
This thread was automatically locked due to age.