Hi, my topology is very simple, and I' ve purchased the fortinet 60c to test in order to have it deployed at all of my locations. Right now, the main features that are most attractive are the dual wan, in order to increase reliability of the vpn. I have 2 WANs in use on the fortinet that I want to VPN connect to a linux box. If WAN1 fail on the fortinet, I want WAN2 to come up immediately, to keep the connect alive. I am finding out the hard way that this is nearly impossible is the VPN at the other end is not another fortinet unit. The question I pose in this thread is to be able to shut down VPN tunnel 1 that' s binded to WAN1 if WAN1 goes down, while bringing up VPN tunnel 2.
So, because my linux box at the other end does not support dead peer detection, the DPD setting AND the monitor-phase1 setting is not used. Therefore, I' m trying to use Dead Gateway Detection to shut down ipsec interface VPN tunnel 1 if WAN1 goes down, and vice versa. However, this doesn' t look like it' s possible.
The frustrating thing is, as I' ve described in my other thread, is that if both my WAN interfaces are in DHCP mode, then the WAN routes are removed from the routing table along with the binding VPN tunnels if the WAN connection goes down. When both my WAN interfaces use a static IP address, and a WAN goes down, then the fortinet does NOT remove the binding VPN route which then stays in the routing table, not routing traffic. So, I' m trying to figure out any way possible to take down a VPN tunnel if the binding WAN interface goes down, and I thought DGD was an option.
I' m looking for any suggestions - right now fortinet tech support just suggested to me that I purchase another fortinet to use at the other end of the tunnel, and i was hoping for another solution.