Hello,
We have a live system which is working fine, this question relates to our dev system (running 8.6.0.6 custom code)
The dev system consists of an MM and currently 2 clusters - one cluster (A) has a single 7010 and is running fine, cluster B however has issues - we recently repaced the single 7010 in this cluster with a 7220. The 7220 seems to be unable to form a tunnel with the MM. I ran "write erase all" and ran through the full set-up as normal but when it comes up, although it can successfully ping the A cluster member, and other devices (including 8.8.8.8), it cannot ping the MM. Weirdly the MM _can_ ping it though it's a bit hit and miss.
In the MM logs there are lots of these relating to the new MC:
Mar 31 23:06:32 isakmpd[31225]: <103103> <31225> <WARN> |ike| IKE SA Deletion: IKE2_delSa peer:x.x.x.x:4500 id:2962618954 errcode:ERR_IKESA_EXPIRED saflags:0x51 arflags:0x0
There is a complication(!) which is that we have just also installed a Fortigate FW - at the moment only the cluster A mngmnt VLAN and the MM mngmnt VLAN have been moved to the FW. The Cluster B mngmnt VLAN SVIs are still on the routers (there are 4 routers just to make it entertaining). I don't really understand how a FW would be involved in breaking the tunnel - the chap who set it up says he can see traffic on port 4500 getting through. And there shouldn't be anything blocking ping etc between the VLANs. I did Google and there were a few similar sounding things involving Cisco ASA.
I can ping from the router directly to the MM when I use the cluster B mngmnt VLAN as the source interface.
I should mention we actually installed 2 7220s in cluster B - I have the same issue with both of them.
I'm wondering if this rings any bells with anyone?
Thanks
Guy
------------------------------
Guy Goodrick
------------------------------