Dual IPSec to same subnet for redundancy
Hello,
We have a site called A and a site called B. On the A site, we have two different ISP router and on the B site, we have a Fortigate firewall. We have for the moment a site to site VPN IPSec. Site A has a LAN 10.10.0.0/16 and site B has a LAN 10.20.0.0/16
What we want to do, is two IPSec tunnel from site A to site B (so 10.10.0.0/16 to 10.20.0.0/16 on both VPN) for redundancy purposes.
The thing is, since on site A we have two ISP, we do have two WAN IPs, but on site B, we have a single WAN IP. So both IPSec VPN will go to the same WAN IP on our fortigate (located on site B).
Is that possible to do? If so, can we implement this in a failover and/or in a load balancing topology?
Do I need to implement GRE tunnels over IPSec for routing purposes?
Thank you for all the help!
PS: On site A we have a WAN load balacing, by the way.
