Hello,
Currently i have 2 branch offices connected with IPSEC site-to-site link, and all was working flawlessly.
Last time ISP proposed to us to setup a dedicated link for us.
Now everything is setup on ISP side, and we have deisgnated VLAN. Isp Prepared untagged port on their devices in both locations.
Now im looking for the most efficent way to set this up. I would like to not use IPSEC over that link, to avoid bottlenecks. Link for the most part will be used to transfer VM backups between sites.
We would like to keep ipsec tunnel through WAN interfaces as a backup for connectivity.
I Have 40F devices on both sides
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @rlshd ,
You can use the ipsec tunnel on your wan interface and dedicated interface. If you want to create a backup connection on the wan link you have two options for that.
You can configure sd-wan or link monitor. If you want to get more information about that, you can review these documents.
https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/19246/sd-wan
Hi @rlshd,
You can have 2 tunnels, 1 through WAN and 1 through the dedicated link. Please refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Implement-IPsec-Backup-Tunnel/ta-p/245084
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.