View Single Post
  #2 (permalink)  
Old 2008-06-13
firewallstarter firewallstarter is offline
Junior Member
 
Join Date: 2008-04-20
Posts: 2
Rep Power: 0
firewallstarter has an average reputation (10+)
Default Re: Phase 2 problems after firewall failover

This issue has been resolved successfully.

The problem was a combination of 2 configuration settings.

1. On the backup firewall the "Accept connections to VRRP IP address" wasn't enabled in IPSO. This should be enabled.

2. On the firewall cluster object the parameter "ike_support_crash_recovery_sr" was set to false. This should be set to true. This setting must be changed through the GUIDBedit tool or through vi.
Reply With Quote