Support Center > Search Results > SecureKnowledge Details
Traffic does not pass via the VPN tunnel after upgrade to R76 Technical Level
Symptoms
  • Traffic does not pass via the VPN tunnel after upgrade to R76 in ClusterXL Load Sharing configuration with Sticky Decision Function (SDF) set to 'IPs'.

  • Traffic capture with TCPdump shows NAT-T packets on UDP port 4500 on both members.
    Traffic capture with FW Monitor (without '-p all' in the syntax) does not show these NAT-T packets on any of the cluster members.

  • Cluster debug (fw ctl debug -m cluster + df drop pivot) shows that both cluster members drop the packets from the client with "fwha_df_chain_module: dropped by DF module".
Solution
Note: To view this solution you need to Sign In .