While turning up new Wan links in VeloCloud edges, we notice that the Cloud Security Service automated deployment is not triggered.
The issue is observed when the CSS tunnel protocol is GRE. The IPSEC CSS automation works fine. Issue manifests only when a new wan link is added to an already activated edge having CSS enabled.
The edge is not triggering the automation process towards VCO when the protocol is GRE.
Issue is tracked under 148351. The issue will be fixed in upcoming VeloCloud edge releases. The below workaround would help in fixing the issue:
- Disable CSS by turning off the toggle on the UI and then turn it back on. This would trigger tunnel creation in all the WAN links.
Affects VeloCloud Edge versions 4.x and 5.x