How to Configure Redundant IPsec Tunnels over SD-WAN Links
Hello Fortinet Community,
I have a setup with two WAN connections that are part of an SD-WAN virtual interface. On each of these WAN links, I’ve configured a site-to-site IPsec VPN tunnel to a remote location. The phase 1 and phase 2 settings for both tunnels are identical, except for the WAN interface used.
My goal is to achieve redundancy between these two IPsec tunnels—so that if the primary tunnel goes down, traffic automatically fails over to the secondary tunnel. Could anyone guide me on how to properly configure this redundancy within the SD-WAN framework? Should I use performance SLAs, specific SD-WAN rules, or routing strategies?
Any detailed guidance or configuration examples would be greatly appreciated.
Thanks in advance!