Partially-redundant IPsec tunnels via different ISPs?
Good day,
I'm trying to understand, if it's possible to make FortiGate, connected by 2 ports to 2 different ISPs, to have parallel 2 VPN tunnels to the same remote gateway - each tunnel via another ISP. The "Partially-redundant route-based VPN example" page seems to explain similar scenario, but here's a detail I miss there:
FortiGate1 has two Internet-facing ports:
[ul]FortiGate2 has single Internet facing port, with IP 172.16.30.1.
The page instructs to configure 192.168.10.1 as default gateway (to 0.0.0.0/0). So IP of FortiGate2 is obviously reached via this next-hop.
Now let's assume that something in ISP1 broke down and the Tunnel1 is down. DPD will detect that, but I see nothing in this configuration that will tell FortiGate1 that now it needs to deliver IPsec packets to the next-hop of WAN2, 172.16.20.1.
There's nothing that can update the routing table of FortiGate1 to tell it that from now on the route to 172.16.30.1 lies via 172.16.20.1.
So how it's going to work?
Thanks,
Vladimir.
