Description

This article describes a behavior seen when using the VPN failover mechanism seen in KB29211 [juniper.net].



Symptoms

As expected, when the primary gateway goes down, the tunnel fails over to the secondary gateway, but when the connectivity for the primary peer is restored the tunnel does not fail back to the primary.

Solution

This is expected, the failover mechanism used is simply DPD, its not a stateful failover mechanism, if what is the active gateway at the moment either IKE-Times-Out or DPD-Times-Out, DPD will do the failover to the other configured gateway (notice that there's only one VPN active at any time), then the same applies here, the failover back will only occur on timeout even though if the SRX tried to build back the other tunnel it would be able, but the SRX is not checking. This is a very static failover that does not differentiate between "Primary" and "Secondary".

If a more dynamic failover is needed, this other setup may help: KB29227 [juniper.net].

Modification History

2025-03-03 : Article Created

Related Information

https://supportportal.juniper.net/s/article/SRX-Example-Configuring-site-to-site-VPN-redundancy-with-multiple-addresses-in-the-gateway?language=en_US

https://supportportal.juniper.net/s/article/SRX-Example-Configuring-site-to-site-VPN-redundancy-with-multiple-addresses-in-the-gateway?language=en_US