Skip to main content
JayWinksInLine
New Member
June 10, 2015
Question

Link Health + IPSec for MPLS redundancy?

  • June 10, 2015
  • 6 replies
  • 6668 views

Running 5.2.3. Have a HQ location and 6 satellites. Each location has an MPLS leg back to HQ. Customer would like to have link monitors on the MPLS so that if something happens in the private cloud they have IPsec failover tunnel come up. I have tried setting this up at HQ with link monitors but all the MPLS routes from HQ are via a single local gateway, so I can't update routing table based on link monitor. Am I going about it the wrong way?

 

    6 replies

    hklb
    Visitor III
    June 10, 2015

    Hi,

     

    I have the same topology to my customer, and I've configured OSPF with BFD.

     

    The convergence is very fast and the solution is very stable

     

    Best regards

     

    Lucas

    JayWinksInLine
    New Member
    June 10, 2015

    Lucas, if there were any way you could share the pertinent pieces of the HQ and satellite configs, I'd be very grateful.

     

    Regards.

    hklb
    Visitor III
    June 10, 2015

    There is a documentation about that : http://docs.fortinet.com/uploaded/files/1693/using-redundant-OSPF-routing-over-IPsec-VPN.pdf

     

    I configured the same aera on all remote sites.

     

    edit : 

    for BFD : http://docs-legacy.fortinet.com/fos50hlp/50/index.html#page/FortiOS%205.0%20Help/routing_dynamic.023.32.html

    Adjust the BFD according your internet line (latency for exemple)

    JayWinksInLine
    New Member
    June 10, 2015

    Yeah that's a little different than my setup, where one of the links is not IPsec but routed over MPLS. I'll see how much I can mold to that.

     

    Thanks

    hklb
    Visitor III
    June 10, 2015

    You need to check with your MPLS provider if you wan to configure ospf with BFD. 

     

    but I always configure IPSEC, even the traffic is on MPLS because the traffic isn't encrypted in MPLS line.. 

    emnoc
    New Member
    June 10, 2015

    Very good suggestions.

     

    Keep in mind you need understand both  the limits/objectives w/dynamic routing protocols and bfd  & the what/where they fit in.

     

    Keep in mind BFD to  MPLS-PE might not gain you anything, due to the provider routing protocols, you can check if your MPLS provide provide lsp-pings and how they release routing information within their labels domains.