Routing/Failover Question
I support a client whose main office is connected to their datacentre through a fiber point-to-point link.
The P2P link, has a small /30 network on each side, on their Fortigate and traffic is routed between their main office and datacentre over the PwP link. Their main office and datacentre each have clustered Fortigates running 6.0.8 firmware.
There's failover VPNs on each cluster in the event of point-to-point failure (which has happened from time to time).
Their current setup will only ever failover to VPNs if there's a hard failure of some type which will almost never happen because the firewall connections are coming in through switch VLANs and those switch links never go down.
I wanted to look at setting up failover using Link Monitoring for their P2P and one of the VPNs on each side, but running into some difficulties and a ticket to TAC just confused me more :) In theory I think this should be fairly easy.
1) Add an IP to each side of the VPN.
2) Setup link-monitor to ping something on each side of the VPN and P2P.
3) Failover when this something fails.
Issues:
A) On the VPN tunnel link, I can only assign a /32.
B) I can easily ping the interfaces on either side - so the tunnel is functioning. But what can I ping besides the interfaces to validate link? And if I do that - don't I also need to make the pings work over the P2P link?
C) There's already a link monitor on both firewalls monitoring WAN availability - will this other link-monitor interfere with this?
Thoughts? Maybe there's a better way to do this I haven't considered. I've thought about converting their WAN failover to SDWAN but there's a lot of work behind this due to the amount of NATs/Policies already in place on each side.
Thanks for anything you can offer.
