Immediate IPsec VPN Primary & Secondary Failover
Hi Team,
I am facing an issue that our some services are cloud based like SAP and i have two WAN links in my FortiGate so that's why I configured two IPsec VPN connections (primary & secondary by using two different WAN links) between Cloud and our FortiGate. I used "Set Monitor" command for failover in secondary IPsec VPN configuration which will monitored primary IPsec VPN connection. I set the two static routes for accessing cloud based server, 1st static route is set for access cloud based server via Primary IPsec VPN connection with AD value is 10 and the priority value is 1, and the 2nd static route is set for access cloud based server via secondary IPsec VPN connection with AD value is 10 and the priority value is 10 to use route when primary down. After that both IPsec VPN connections are working fine and properly auto failover but the issue is that this failover takes few seconds to shift the traffic from primary to secondary which causes our users will disconnect from their established connection from cloud based SAP service. I want to configure this failover will occur immediately without any delay to prevent disconnection issue from cloud based SAP service. Please guide what can i do and how to check failover threshold and is it edible.
FortiGate Model: 201F
Firmware Version: 7.0.10 build0450
