IBM Cloud Docs
Why isn't the service route for my VPN gateway correct?

Why isn't the service route for my VPN gateway correct?

For a policy-based VPN gateway, service routes are propagated to routing tables that have VPN gateway selected for the Accepts routes from attribute. These routes have names that are prefixed with ibm-vpn-gateway-.

In this rare instance, you might find that these service routes are not correct. For example, the Next hop is not the same as the private IP of your active gateway member. In this case, traffic is broken even if the VPN connection is Active.

The VPN gateway service keeps monitoring the health of each VPN gateway. When a fault is detected, the service tries to recover the VPN gateway automatically. The recovery process might fail and cause inaccurate routes to remain.

Follow these steps to fix the service routes:

  1. From your browser, open the IBM Cloud console and log in to your account.
  2. Select the Navigation Menu icon Menu icon, then click VPC Infrastructure > Routing tables in the Network section.
  3. Select your VPC from the VPC drop-down menu.
  4. Click the routing table to open its details page, then click Edit.
  5. Clear the VPN gateway checkbox in the Accepts routes from (optional) section and click Save. Service routes propagated by the VPN gateway are removed.
  6. Click Edit again.
  7. Select VPN gateway in the Accepts routes from (optional) section and click Save. Service routes propagated by the VPN gateway are generated.