Description

Additional SPCs can be installed in the service gateways in a cluster without incurring downtime using ISHU. After performing an ISHU, the existing IPSEC SAs will not be load balanced by default but the new SAs will be. The existing SAs will continue to be anchored on the original SPCs. 

The SAs can be checked using the command, ' show security ike tunnel-map'

For more details, refer to documentation on show security ike tunnel-map.

Solution

The existing IPSEC SAs can be forcefully load-balanced between all SPCs (including the newly added card) by performing one of the following actions:

  • Modify the configuration of the existing VPN (example: change gateway name) or delete and re-add the VPN configuration and commit the changes 
  • Reboot both nodes simultaneously