"No matching IPsec selector, drop" - bad Tunnel Selection
Hi All,
i've recently setup a New site-to-site VPN Tunnel Tunnel Mode on our 200D, in 5.4.
Tunnel is Up and Running and i'm able to reach the remote FW in https and remote Users are Able to reach Local resources.
but, but....
Here is my issue :
there is an UDP traffic which not working correctly, namely SIP traffic (5060).
i'm able to see the Original direction going throuh different VDOMs, but the reply direction on the last VDOM going through the bad Tunnel IPsec and the IP phoone never succeed in registration.
already check diag sni pack during while pinging --> ok
already check diag debug flow while pinging and it is matching the good tunnel :(
already check diag debug flow to see what happens ( UDP 5060 traffic)--> some traces
id=20085 trace_id=2116 func=print_pkt_detail line=4751 msg="vd-VPN received a packet(proto=17, 192.168.XXX.2:5060->192.168.200.XXX:5060) from FWA-FWB. " id=20085 trace_id=2116 func=resolve_ip_tuple_fast line=4815 msg="Find an existing session, id-000574d4, original direction" id=20085 trace_id=2116 func=npu_handle_session44 line=904 msg="Trying to offloading session from FWA-FWB to VPN-jun, skb.npu_flag=00000400 ses.state=00000010 ses.npu_state=0x00040000" id=20085 trace_id=2116 func=__ip_session_run_tuple line=2790 msg="run helper-sip(dir=original)" id=20085 trace_id=2116 func=ipsec_tunnel_output4 line=1176 msg="enter IPsec tunnel-VPN_site1" id=20085 trace_id=2116 func=ipsec_common_output4 line=766 msg="No matching IPsec selector, drop"
as you can see, the traffic going through tunnel VPN_site1 instead of my VPN_site2 which is temporarily down.
how this can be possible?
what another i can check ?
how to solve this?
thanks in advance for any help.
Regards,
Phi.

