Table of Contents
< All Topics
Print

【WANO】Unable To Access Peer Side With Sangfor VPN Due To PBR

Issue Description

Unable to access to peer side even with Sangfor VPN built-up

Error/Warning Information

  1. Original environment was using MPLS
  2. Original settings was route to peer side by using Policy-based Route(PBR)
  3. After unplug MPLS link, traffic unable to access to peer side
  4. Confirmed that Sangfor VPN is built-up

    Handling Process

Root Cause

Policy-based Route priority is always higher than VPN route. From above scenario, it is due to the PBR has higher priority and the traffic matched with the PBR first, causing the traffic to route to the MPLS first.
file

Solution

Remove the PBR or make necessary adjustment to not include LAN segment to prevent the traffic matches PBR first.

**Note ***
Route priority for Sangfor WANO:

  1. Policy-based Route
  2. Static/Direct Route
  3. unnel Route
  4. VPN Route

Note: Route priority may vary with different Sangfor Product.