Firewall policy switching on IPSec tunnel rebuild or WAN down/up
- September 30, 2015
- 5 replies
- 6141 views
Hi,
Here is the scenario:
- I have a site-to-site IPSec tunnel between two 60D's which carry video in the tunnel
- I have the following policies setup on the sending unit: 1) internal to VPN (Encoder_local_LAN to Decoder_remote_LAN ALL) 2) VPN to internal (Decoder_remote_LAN to Encoder_local_LAN ALL) 3) ssl.root to any (user group restricted portal access) 4) internal to wan1 (ALL) - My video traffic is always supposed to use policy #1 and does when the tunnel is first established The issue I'm occasionally seeing is that on IPSec key refresh, tunnel rebuild of wan down/up policy #4 is chosen instead of #1. When this happens the VPN tunnel appears healthy, but the video payload is being sent directly out wan1 instead of the tunnel. I have several of these setups and some work for months without a hiccup, others will run for a few days before the issue occurs. Disabling policy #4 immediately fixes the problem, but I need the policy for non-VPN traffic. Currently I have two 60D's at the same remote location exhibiting the same behavior, one is running fw v5.2.3b670 and the other fw v5.0b318
Has anyone seen this before?
I'm attaching a sanitized config of one of the remote units.
