> Source: [sk36544](https://support.checkpoint.com/results/sk/sk36544)

# sk36544 - VPNs fail after a failover in CP cluster uses 3rd party cluster solutions (GAIA VRRP / IPSO VRRP and IP clustering)

| Property | Value |
|----------|-------|
| Solution ID | sk36544 |
| Date Created | 2008-12-16 |
| Last Modified | 2023-03-15 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- VPN tunnels are failing following a failover.

## Cause

The *fwha_sync_outbound_sa* setting in the $FWDIR/conf/objects_5_0.C is set to *false*.

The outbound security association keys (outbount IPsec SAs) used to encrypt the traffic are not synced to the standby member in 3rd party clustering solutions (GAIA VRRP or IPSO VRRP and IP Clustering).

When the failover happens, there is no valid SA for the connection as the new active member doesn't have the required IPsec SA keys for encryption.

The connection will not established till a new VPN tunnel (QM) will be negotiated to create new IPsec SAs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
