Skip to main content
g3rman
New Member
August 15, 2017
Question

Survivable Sessions with multiple VPN Tunnels

  • August 15, 2017
  • 1 reply
  • 2866 views

We have 2 VPN dialup tunnels setup from a remote office to our data center.

Routing is dynamic via OSPF and working correctly.

We do have a number of very long lived connections (such as Remote Desktop sessions, SSH and other for example) that break whenever the firewall switches from the primary to the secondary VPN tunnel due to the WAN1 interface going down.

 

In the past we had Cisco DMVPN routers setup which are non-stateful and therefore the sessions would automatically resume across a different path. Now with the stateful Fortinets in place this is becoming more of an issue.

Yes, the primary circuit is somewhat unstable, but there isn't anything we can do about it at the moment.

 

I'm wondering if other people have come across the same situation and how it was resolved.

1 reply

bommi
New Member
August 15, 2017

I am not aware of any other solution than converting your fortigate into an stateless firewall:

 

http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-networking-54/Interfaces/VLANs/Asymmetric%20routing.htm

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!