Forum Discussion
IPSEC Affinity Not Working
I have an HA LTM in load balancing Cisco DMVPN connections to four hub routers 10.20.1.101, 2, 3, & 4. Problem is that it's load balancing the ISAKMP and ESP to different hub routers, as you can see from the connection table. What's the simplest way to get the ISAKMP/ESP from the public source address (left) to the same hub router (right)? I have a simple configuration with a vip, one pool with four members and no snat, let me know if you need to see more. THANKS!! [root@etc-rslb-dmvpn-1:Active:Changes Pending] config tmsh show sys connection | grep 172.16.1.10: 99.126.100.55:500 172.16.1.10:500 99.126.100.55:61936 10.20.1.104:500 udp 5 (tmm: 1) 99.108.26.170:500 172.16.1.10:500 99.108.26.170:500 10.20.1.101:500 udp 5 (tmm: 3) 99.126.100.55:4500 172.16.1.10:4500 99.126.100.55:35306 10.20.1.103:4500 udp 4 (tmm: 1) 99.108.26.170:4500 172.16.1.10:4500 99.108.26.170:50000 10.20.1.103:4500 udp 4 (tmm: 3) 108.86.114.132:4500 172.16.1.10:4500 108.86.114.132:23287 10.20.1.104:4500 udp 0 (tmm: 3)
11 Replies
- What_Lies_Bene1
Cirrostratus
v11.3 with the latest hotfix would be best and shouldn't cause any issues. v11.4 seems to have introduced some changes that I'd want to avoid for now.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com