Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SD-WAN Profile failback with VPN Does not work.

Hello Dear Partners!

I configured an SD-WAN Scenario with Two VPN Tunnels and then created an SD-WAN Profiles. as the image below:

I did the following Test I dropped the Main Link VPN_MTZ_1 and Sophos Quickly switched the Route to the Backup Link VPN_MTZ_2.

But when I returned the Main link that is certainly the link with lower latency because it is an end-to-end fiber. Sophos simply keeps all the traffic through the Backup route and does not obey the order of the Tunnels and does not perform the Failback.

It simply keeps all traffic being routed through the Backup Tunnel instead of re-establishing the route through the Main tunnel, as its performance is proven to be better as shown in the image below:

Unfortunately I see this as a serious failure of our SD-WAN that Failback has to work very well.

Conclusion: for Sophos to return the traffic through the Main tunnel to the router, I have to take down the Backup VPN tunnel, which is a Manual procedure.



This thread was automatically locked due to age.
Parents
  • Dear Fagner,

    This is Moheed from Sophos.

    Reason you are not seeing switchback to primary link is because the switch-back is ONLY triggered in case latency-difference is more than 10ms.  Likewise if its a 'Best profile with jitter sensitivity margin is 5ms and for Best profile with packet-loss as sensitivity margin is Zero percent.

    This is by design and it is there to avoid unnecessary link flap in case of links have varying sensitivity.

  • Perfect Moheed! Now I could understand this behavior very well. and really this is not between the lines of the documentation but with your feedback it was enlightening.

    Fagner Nascimento (Sophos Architect)

    Novatera - www.novatera.com.br

Reply Children