Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XFRM Interface flapping after HA failover

Hi all,

today I made an manual failover to the auxiliary device. On the auxiliary device the XFRM interfaces began to flapping. On both tunnel ends I had many interface up and down events (ervery few seconds). The IPSec Tunnel itself seems to be stable (WebAdmin shows a green status). Both firewalls shown the tunnel as up. OSPF shows no neighbors available. 

After I switched back to first device, the XFRM interfaces become stable and most tunnels are back online, some tunnels needed manually restarted to work again.

The HQ firewall is an XGS5500 with SFOS 19.0.1. Most site firewalls runs also on 19.0.1. We have also some firewalls witch runs on SFOS 19.5, these boxes had also the flapping XFRM interfaces. 

 anybody an idea what this behavior causes?

Ben



This thread was automatically locked due to age.
Parents Reply
  • Hi Vamshi,

    while the firewall runs on the 2nd node, I had multiple interface Down and Up events (Message ID 17813) in the system log but no IPSec Terminated (ID 17802) or Established (ID 17801) messages in the VPN log. So, the tunnel itself was stable.

    OSPF had starts to work, when I has to switched to the first node. Some tunnels needed to stopped and restarted before OSPF saws the neighbors.

    On the XGS5500 are 58 IPSec tunnels terminated.

    Ben

Children