IPSEC tunnel now active when Static route on WAN connection is larger than primary
60D on 6.0.9
I've run into this issue before for other clients and haven't figured it out.
When in a multi-WAN scenario:
Primary Private fiber connection: Wan2 (OSPF) Static Route with Distance of 10
Backup ISP: DMZ static route with a distance of 20
IPsec tunnel on DMZ port with Static route with a distance of 10
This IPsec tunnel will not stay active unless we change the Distance of the Backup ISP to 10?
But this puts our WAN2 and DMZ in a load-balancing scenario, and we want to keep active-passive setup.
How can we keep the backup ISP in a passive state and keep the VPN tunnel up?
