Skip to main content
vstrabello
Explorer
June 30, 2017
Question

Redundant, policy-based IPsec VPNs

  • June 30, 2017
  • 2 replies
  • 4744 views

Is there any way to make redundant IPsec VPNs by using policy-based VPNs?

 

The situation is that customer remote firewall have two links to the Internet and when the main link goes down, there is no commutation of traffic to the now active, backup link, needing to move it's respective policy before the downed policy to keep the traffic going between the locations.

 

Or just say, a route-based IPsec VPN would be enough?

 

Thanks!

 

Vitor

    2 replies

    EMES
    New Member
    June 30, 2017
    Route based all the way.
    neonbit
    New Member
    July 1, 2017

    +1 for route based.

     

    Create a VPN zone and put both IPSEC interfaces in the zone. You only have to create one set of policies for both VPNs now.

     

    DPD (dead peer detection) is enabled by default, but the default value will only failover after 60 seconds. I'd recommend putting the timers down if you want the failover to happen quicker.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!