Skip to main content
boozely25
New Member
September 10, 2018
Question

Fortigate 60E - failover route to same subnet

  • September 10, 2018
  • 1 reply
  • 2822 views

I have a site to site vpn(Tunnel 1) setup over a private  elan circuit(layer2). Everything is routing fine from Lan 1 to Lan 2.  We added a second elan circuit and want to set up a second site to site vpn(Tunnel 2) and set up routing so that if the original vpn goes down...the second one can be used.   Is it possible to setup the configuration attached and accomplish this?

i.e   Using Tunnel 1

192.168.1.10 --->192.168.21.1-->192.168.21.3-->192.168.11.10 - working fine

 

if Tunnel 1 goes down, use Tunnel 2

 

192.168.1.10 --->192.168.50.1-->192.168.50.3-->192.168.11.10

 

 

    1 reply

    sw2090
    SuperUser
    SuperUser
    September 11, 2018

    I do this here with Priority based routing.

     

    I have two IPSec VPNs to each shop and I have two routes for to reach each subnet over there. They have the same distance but different priority. Primary the one with the lowest priority is used for the traffic. If that IPSec Tunnel drops down it will switch to the second route  with minor latency. Once Tunnel 1 comes back up it will be used again due to routing priority.

    Works fine here with FGT90 and 100(E)s and v5.4.x 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.