Unable To Access Peer Side With Sangfor VPN Due To PBR

|
  • 135
  • 6

Issue Description

Unable to access to peer side even with Sangfor VPN built-up

Handling Process

  • Original environment was using MPLS
  • Original settings was route to peer side by using Policy-based Route(PBR)
  • After unplug MPLS link, traffic unable to access to peer side
  • Confirmed that Sangfor VPN is built-up


Root Cause

Policy-based Route priority is always higher than VPN route. From above scenario, it is due to the PBR has higher priority and the traffic matched with the PBR first, causing the traffic to route to the MPLS first.

Solution

Remove the PBR or make necessary adjustment to not include LAN segment to prevent the traffic matches PBR first.

Note *
Route priority for Sangfor WANO:
  • Policy-based Route
  • Static/Direct Route
  • Tunnel Route
  • VPN Route



Note: Route priority may vary with different Sangfor Product.
Faisal Posted 26 Aug 2020 08:20
  
Thank you very much for the information ...
Faisal Posted 16 Oct 2020 09:32
  
Nice article ...
Faisal Posted 23 Dec 2020 07:58
  
Great info ...
Ellechar Lv4Posted 19 Jan 2021 09:31
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 25 Mar 2021 07:11
  
Very informative …
Faisal Posted 10 Jun 2021 08:51
  
Nice guidance ...

I want to write a case
Doc ID: 2403
Author: CTI TF
Updated: 2019-12-23 16:25
Version: