Ipsec tunnel between sonicwall and cisco on failover to other wan ip ping passes but other flows sto
So i have a Sonicwall with two wan IPs on one end and a Cisco router with two other wan IPs on ther end. VPN works fine and when i kill a link on any side i loose a couple of pings and vpn is re-established so all seems good and as expected.
However on many occasions when VPN is re established i can start pinging a host on network 1 from a host on network 2, but acessing a client server application on network 1 (same host I am pinging) from a host on network 2 (same host from which i am starting ping) does not work i.e. i can ping host but cannot connect to a service on host. As soon as i disable and re-enable the vpn connection on sonicwall all works fine. It looks like sonicwall is keeping some flows bound to the 'old' vpn 'route' and need to manualy turn vpn off and back on. Any suggestions?
Am on latest firmware..
Answers
A few things that might help:
Is this one VPN policy with multiple peers, or are you using multiple tunnel interfaces + route policies?
OK, you can disregard the bit about triangular routing if this is only a single tunnel.