Hello all,
We attempted to setup an ASG 220 with a 2nd Internet connection. This site currently has 2 site to site tunnels to remote offices running ASG 120's. All sites running 7.512.
I added the 2nd connection, first on eth4 and then on eth2. Enabled uplink balancing. NAT was set to uplink Interfaces.
On the remote firewalls I created an availability group with the 2 IP addresses on the main firewall and used that for the remote gateway definition.
The tunnels would not come up. I tried to set the tunnel to use the new Internet connection only, but that did not work either.
In the Live Log I was seeing an error:
ERROR: ... Errno 1: Operation not permitted (I'm omitting the IP info here)
The new Internet connection was listed first in the uplink balancing and in the Availability group.
Auto packet filter rules were enabled for the tunnels.
Not sure what I'm missing here. Is it possible that the ASG only want to use the original WAN connection for the tunnels?
I have used uplink balancing successfully in the past, but never with a site to site tunnel.
Other traffic was working correctly, ie web browsing, email, etc.
Thanks!
David
This thread was automatically locked due to age.