Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chrisn
New Contributor

IPSEC VPN and backup internet - or OCVPN?

We are planning to add 4G backup internet service to our two locations. Currently, we have an IPSEC VPN between the two locations. What is the best way to configure the VPN to fail over to the backup internet?

 

I was looking over the guide for redundant VPN connections (https://help.fortinet.com..._Overview.htm#Creating), and it call for setting up up 4 VPN connections on each host. But it also says that the configuration is for equal cost connections, which our 4G backup would not be.

 

The guide then describes backup IPSEC interfaces, which looks like what I want. But it only covers setting up a backup to one VPN, though. Is it possible or recommended to "daisy-chain" the other two redundant VPNs to each other? For example, see the following...

[ol]
  • Site 1 A -> Site 2 A (Primary)
  • Site 1 A -> Site 2 B (monitoring tunnel 1)
  • Site 1 B -> Site 2 A (monitoring tunnel 2)
  • Site 1 B -> Site 2 B (monitoring tunnel 3)[/ol]

    I am afraid that if, for example, the Site 1 A connection goes down, it would take a while for the VPN to switch, since it will first try to connect with tunnel 2, before it will try tunnel 3.

     

    Of course, this is all assuming I should update the current IPSEC VPN to work. With version 6.0, we now have the Overlay Controller VPN. Should l nuke my current IPSEC VPN and switch to that? I am a bit reluctant to do that at the moment, since I can't try it out without removing the existing VPN configurations, but if it saves me a bunch of headache setting up the backup VPNs, maybe it would be a good idea...

  • 0 REPLIES 0
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors