| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Online Status For 86403433 Posted July 17, 2006 04:57 AM Hi everybody, we are trying to implement a HA VPN tunnel between our NGX R60 HFA03 cluster and two VPN1 Edge devices. Unfortunately i wasn´t able to find a guide how to do that. Both boxes are connected to a router as primary WAN connection and the backup is PPPOE dsl. I configured both gateways as dynamic ip devices and the topology on both boxes a network object that defines the used network. Each Edge is configured as backup gateway of the other Edge. I created a star vpn community with the R60 cluster as center gateway and the two edges as satellite gateways. When i remove the internet connection on the primary box it fails over to the backup and the normal internet traffic is working. But the vpn traffic does not work. In smartview tracker i can see the following log entries: encryption failure: Wrong peer gateway for decrypted packet (VPN Error code 01). When i go to smartview monitor and take a look at the tunnels of our cluster i can see a tunnel to the primary and the secondary Edge and both are showing as "up". Perhaps my configuration is wrong - can anyone help me ? kind regards, Alex |
| |||
| I found this doc regarding the setup procedure. It's for 5.0 but looks similar to the 6.0 code. You can access it from sofaware's webiste here: Sofaware KB: EmbeddedNG_High_Availability.pdf I'd be interested to hear what success you have. |
| |||
| thanks for this doc but this is not really what i am looking for. the ha configuration on the edges is pretty easy and straight forward. My problem is how has the configuration in smartcenter have to look like so that i can establish a ha vpn. |
![]() |
| Thread Tools | |
| Display Modes | |
| |