Issues with VRRP VIP and policy installs At a remote site, I have a 2 member VRRP cluster (IPSO 3.9, NGX R60 HFA 2). Sometimes when I push a policy to the cluster, traffic to the cluster starts to be routed through the secondary firewall instead of the primary. The primary firewall is still VRRP master on all interfaces and the secondary fw is still the VRRP backup on all interfaces. Is it possible that the Virtual IP MAC address is some how getting corrupt or changed in the router that feeds the firewalls? Any ideas would be helpful. |