3rd party tunnel keeps flapping intermittently between two data centers
1571
Created On 06/25/21 11:49 AM - Last Modified 02/29/24 00:19 AM
Symptom
- 3rd party tunnel keeps flapping intermittently between 2 Data Centers (DCs) when both side IONs act initiator as 'NO'.
- Alerts thrown in UI are shared below in the screenshot:
- Reasons for 3rd party tunnel flaps will show the extended state as "Multiple IKE Session".
- In tunnelmgr (CLI command: file view logs tunnelmgr) error logs will be as:
"_fac":"tunnelmgr","_level":"INFO","_msgid":"SetServiceLinkStatus","_pid":2627,"_prog":"tunnelmgr","_ts":"2021-06-17T11:54:00.231Z","sl":"sl1","state":{"extended_state":"multiple_ike_session","local_ip":"xx.yy.zz.mm","remote_ip":"xx.yy.zz.qq","state":"down"}} {"_fac":"tunnelmgr","_level":"INFO","_msgid":"StateTunnelDown","_pid":2627,"_prog":"tunnelmgr","_ts":"2021-06-17T11:54:00.232Z","event":"EVENT_TUNNEL_DOWN","sl":"sl1"} {"_fac":"tunnelmgr","_level":"INFO","_msgid":"ignore this event","_pid":2627,"_prog":"tunnelmgr","_ts":"2021-06-17T11:54:00.232Z","event":"EVENT_TUNNEL_DOWN","sl":"sl1","state":"TUNNEL_DOWN"}
-
As DC-to-DC native VPNs are not supported so we build a 3rd party tunnel between 2 DC's.
Environment
- Prisma SD-WAN
- VPNs
- Tunnel between Data Centers
Cause
- 3rd party tunnel keeps flapping intermittently between 2 DC's when both the side IONs act initiators as NO (as seen in tunnelmgr logs)
- Between DC TO DC service links can run into multiple IKE session hence the flap
Resolution
- For Temporary fix, Make one site as default config and another DC site as "initiator only =Yes", then the 3rd party tunnel remains UP and stable.
- For Permanent Fix, Upgrade the Ion device to 5.6.1. The issue has been resolved in code 5.6.1.
Additional Information
28 Feb 24 (Vijay) - Article reviewed with Namratha and published external.