- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FG-70F to able to support two IPsec VPN in active active mode via different ISP
Need to understand if the FG-70F in my hand can be able to support two IPSEC VPN via WAN interfaces connected to two different ISP in active active mode (with load balancing).
This is branch and at central side we have other FG with different model but same motive.
Please let me know how is it possible to implement this.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Are you able to provide more information. Like a topology, are these members part of SDWAN zone.
Please check the following article for redundant :
You can definitely check by unsetting monitor main_VPN in the documentation
set monitor main_vpn
Regards,
ajoy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ajoy,
In our case the two sites are geo separated (different country) for example HQ1 in India and HQ-2 in USA is this solution feasible?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you want simply load-balance between two paths and don't want to manipulate much, I would recommend IPsec Aggregate below:
https://docs.fortinet.com/document/fortigate/7.2.9/administration-guide/779544/packet-distribution-a...
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Toshi,
LB with different internet link (different BW) will work in this case?
if yes then its good for me
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It doesn't matter what kind of internet circuits those are as long as each has reachability to the other end.
Toshi
