Hello,

Once, and to show that this list is not fated to "i got a trouble", I can
say that my configuration (Cluster of 2 nokia IP710) works! In cause : on
both members and cluster, the primary address should be the external one.

But ... I wonder if you encountered the same trouble as I did : I'm now
playing with the Fail-over : I unplug cable, shot machine off and so on.

In same case (both in VRRP configuration or in Nokia Clustering
configuration), established VPN seems to refuse to continue to work.

The VPN peer is a cisco. In the logs, I can see messages like "Decrypted
packet failed SA identity check" and "Decrypt: replay check failed
connected id=2000".

I can also see in those logs that the last VPN packet received is
originated from the physical IP of the interface and not from the Cluster
IP.

It happens mainly on VRRP recovery (very very easy to reproduce).

The "solution" is to send a packet from the remote net to the local
one. It seems to trigger the VPN from "pondering about life and
everything" to "working again from a cluster's view".

Any idea ?

JF

--
Jean-Francois Gobin - Administrateur gobinjf.be
http://www.gobinjf.be   mailto:[EMAIL PROTECTED]

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to