Reachability Issue Between Head Office and Branch IP After IPSec VPN Reconfigure
Hi,
I’m encountering a reachability issue between our Head Office and Branch Office following changes to our IP Sec VPN setup.
Specifically, the public IP of our Branch Office b-b-b-b is no longer reachable from our Head Office IP h-h-h-h. However, b-b-b-b remains accessible from other external sources, indicating that the branch connection is working outside the Head Office route.
This issue began after we deleted and reconfigured the IP Sec VPN on the Head Office firewall. Since then, the VPN tunnel fails to establish due to unreachability.
Notably
1- If I set up policy-based routing from the Head Office, I can reach b-b-b-b
2- However, with this routing, the IP Sec VPN tunnel fails to work.
3- I’ve verified that there are no deny policies, including local-in-policy, and the IP is only used in the IP Sec configuration.
Ping response from Head Office firewall:
execute ping b-b-b-b
send msg failed: 22 Invalid argument
send msg failed: 22 Invalid argument
send msg failed: 22 Invalid argument
send msg failed: 22 Invalid argument
send msg failed: 22 Invalid argument
Could you please advise on how best to proceed with diagnosing and resolving this issue?
Thanks,
Rohit K
