Skip to main content
EricTheGreat
Visitor III
June 14, 2020
Solved

Redundant internet/S2S VPN - need some assistance

  • June 14, 2020
  • 9 replies
  • 8356 views

Greetings.  Here is my situation, and I would like some suggestions.

 

We have 2 branch offices. 

 

Branch office 1 has a FortiGate 100F, and 2 internet connections, different ISP's (WAN1 and WAN2 respectively). Branch office 2 also has a FortiGate 100F, but only ONE internet connection (WAN1).

 

I would like to accomplish the following:

 

1. Branch 1 failover internet connection - when WAN1 goes down, traffic is pushed over to WAN2. When WAN1 is restored, traffic jumps back over to WAN1.  Essentially make WAN2 a backup connection...only activated if WAN1 fails.

 

2. Site-to-site VPN connection between the 2 sites, but with redundancy.   So, if 1 of the 2 internet connections goes down at branch office 1, the site-to-site VPN will not be disrupted.

 

What is the best way to accomplish this?  SD-WAN..priorities....CLI magic?

 

I'd appreciate some assistance!

 

Thank you for your time!

 

 

    Best answer by ede_pfau

    Should be possible in v6.0 as well. I wouldn't put v6.2.x into production yet either.

    9 replies

    M_M_SW
    New Member
    June 14, 2020

    you can use SD-WAN

    Combine two lines wan1 wan2 and two VPNs at the same time

    use SD-WAN Rules to make it Priority order or redundancy

    EricTheGreat
    Visitor III
    June 14, 2020

    When you say combine the two VPNs at the same time, what exactly do you mean?

    ede_pfau
    SuperUser
    SuperUser
    June 15, 2020

    You can SLA not only physical lines but VPNs as well.

    You need to create 2 s2s VPNs (as you have 2 different public IPs on one side) of which one will be 'muted' by attaching a higher cost. This can all be done in the SD-WAN setup.

     

    Sorry, no magic needed.

    Aads
    New Member
    June 18, 2020

    Hi Eric,

    I would say this is achievable even without SD-WAN. You can use a routing protocol to manipulate the traffic. You will have to create the below IPSEC tunnels,

     

    FG01_WAN01 <-> FG02_WAN01

    FG01_WAN02 <-> FG02_WAN01

     

    Use a dynamic protocol like BGP over the IPSEC tunnels. Then you can manipulate BGP routes using attributes such as local preferences or AS-PATH prepending. 

     

    You can also use SD-WAN. In which case in Branch office one you will have 2 IPSEC interfaces members in the SD-WAN interface. You can create SD-WAN policies to prefer one tunnel over the other. In this case, you could either you a dynamic routing protocol or static routes. 

     

    Hope it helps. 

     

    Regards

    Aadhil

     

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!