I have a site to site vpn(Tunnel 1) setup over a private elan circuit(layer2). Everything is routing fine from Lan 1 to Lan 2. We added a second elan circuit and want to set up a second site to site vpn(Tunnel 2) and set up routing so that if the original vpn goes down...the second one can be used. Is it possible to setup the configuration attached and accomplish this?
i.e Using Tunnel 1
192.168.1.10 --->192.168.21.1-->192.168.21.3-->192.168.11.10 - working fine
if Tunnel 1 goes down, use Tunnel 2
192.168.1.10 --->192.168.50.1-->192.168.50.3-->192.168.11.10
I do this here with Priority based routing.
I have two IPSec VPNs to each shop and I have two routes for to reach each subnet over there. They have the same distance but different priority. Primary the one with the lowest priority is used for the traffic. If that IPSec Tunnel drops down it will switch to the second route with minor latency. Once Tunnel 1 comes back up it will be used again due to routing priority.
Works fine here with FGT90 and 100(E)s and v5.4.x
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.