Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RED tunnels not restablishing correctly after HA failover

Hi, 

I've recently setup a HA active/passive pair of virtual XG firewalls running in VMware, with a branch office setup with a RED tunnel to the HA pair. 

Every time we trigger failover between the HA firewalls (ie rebooting or when I upgraded the firmware) the RED connection does not reconnect properly. Basically both firewalls report that the RED tunnel is 'up', but no traffic is able to flow over it - not able to ping any devices at the other end of the RED, or the remote firewall (by LAN interface or RED interface). 

This behaviour persists after manually toggling the RED on and off on the HA firewall, but it seems to be resolved by manually deleting and re-creating the static route. 

Both the HA virtual firewalls and the branch office firewall (XGS 116) are running v18.5.3.



This thread was automatically locked due to age.
Parents
  • Hi,
    some questions ...
    "but it seems to be resolved by manually deleting and re-creating the static route." ... which static route? There are only some very special situations where you need a static route with RED.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • Hi,
    some questions ...
    "but it seems to be resolved by manually deleting and re-creating the static route." ... which static route? There are only some very special situations where you need a static route with RED.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?