OK. I have a 8730 at site A and site B has 10 9670 IP Phones. We are running through firewalls that are locking in IPSEC VPN hardware tunnels. I have 2 different WAN connections to SITE A. When we manually fail from WAN1 to WAN2 the firewall sees the old policy from all the 9670 phones keep sending keep alives from destination port 49xxx to 1719 UDP at site A. It appears the phones are not expiring their keep alive thus the firewall cannot tear down that policy and re route over to WAN2.
SO my question is can you within the firmware or settings file adjust the expiration or timing to a lesser value? Why won't they stop the keep alives from destination port 49xxx to 1719 UDP without unplugging/plugging the phone back in.
To recap: Site A has S8730 and site B has 10 9670's. IPSEC VPN tunnels via firewalls at both sides. Dual wan connections at both sides. When we disconnect WAN1 all data fails over to WAN2 fine. The 10 IP phones get stuck in connecting and the firewall shows the old policy still up from keep alives from the phones being sent to Site A from port 49xxx to UDP port 1719.
Sorry for the confusion tyring to get all the information in here.
Has anyone tried this or got dual WAN connections working with IP phones at a remote location without unpluging the phone to reset them into the new policy/WAN link?
SO my question is can you within the firmware or settings file adjust the expiration or timing to a lesser value? Why won't they stop the keep alives from destination port 49xxx to 1719 UDP without unplugging/plugging the phone back in.
To recap: Site A has S8730 and site B has 10 9670's. IPSEC VPN tunnels via firewalls at both sides. Dual wan connections at both sides. When we disconnect WAN1 all data fails over to WAN2 fine. The 10 IP phones get stuck in connecting and the firewall shows the old policy still up from keep alives from the phones being sent to Site A from port 49xxx to UDP port 1719.
Sorry for the confusion tyring to get all the information in here.
Has anyone tried this or got dual WAN connections working with IP phones at a remote location without unpluging the phone to reset them into the new policy/WAN link?