cds-snc / notification-planning-core

Project planning for GC Notify Core Team
0 stars 0 forks source link

Challenges in Automatic switching for Site-to-Site VPN Tunnels : Investigating Issues Post AWS Maintenance #258

Open Zaxorinox opened 6 months ago

Zaxorinox commented 6 months ago

I set up a site-to-site VPN connection between our on-premises network (PaloAlto) firewall and private sub in AWS. Initially, both tunnels were established, and the specified traffic flowed smoothly.

However, during routine maintenance by AWS, our VPN was temporarily affected. After the maintenance, although both tunnels showed as established and UP upon rechecking their status, the traffic did not balance between the tunnels.

I tested the option of manually forcing one tunnel to go down by adjusting the Dead Peer Detection (DPD) timeout parameter, which worked but is not the desired solution.

The automatic switch between the tunnels should occur, but it is not happening. What could be the cause of this issue?