Hello,
We have multiple IPSEC site to site vpn in our office. Currently, all our vpn's configured using the 1st ISP link (Our fortinet firewall WAN1 ip as a remote gateway for the vpn). Recently we buy another link and connected to our fortinet firewall WAN2 interface. How i can convert or reconfigure all this vpn with failover concept, like if ISP 1 fails the vpn should work with ISP 2. Kindly need your advice to achieve this. Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I'd be interested in this too.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Your best method is to enable a dynamic routing protocol and assign a /30 or /31 on the vpn links. Treat them like wan links or private line and it will failover with no effort. Just set the metric on what link you want .
hijt: If you have a big enterprise and with multiple subnets being carried you can maybe do a hacked load-balance
e.,g
LINK1 SRC/DST 10.10.10.0/24 <> 10.20.10.0/24 metric 100
LINK2 SRC/DST 10.10.10.0/24 <> 10.20.10.0/24 metric 1000
LINK1 SRC/DST 10.10.11.0/24 <> 10.20.11.0/24 metric 1000
LINK2 SRC/DST 10.10.11.0/24 <> 10.20.11.0/24 metric 100
Or something to that nature of SDWAN is an option but I seen many issues with vpn-interfaces as SDWAN members. I would review this video , upgrade to the latest version and give it a spin
https://video.fortinet.com/latest/sd-wan-dual-vpn-tunnel-to-data-center
Make sure to use a dynamic routing with the vpn-interface if your do SDWAN
YMMV, provide feedback if your SDWAN with vpn-members does not give you any issues.
Ken Felix
PCNSE
NSE
StrongSwan
thanks Ken!
well I already do failover this way with all my point-to-point tunnels. But will surely be helpful to the thread starter.
I'd still be interested to know if that works for dial up tunnels too.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
For site2site dialup yes it would work, we have tunnels (2x ) to SRX that runs private BGP where the SRX are initiator . It works 110% if the time correctly once BGP-KA are lost, and DPD tears down the tunnel.
In the OP, he probably wants to try SDWAN and have two vpn-phase1-interfaces with set remote-gateway <ISP1> in one and <ISP2> in the 2nd.
No matter what you do, I would enable a dynamic BGP or OSPF or heck RIPv2 works fine also just a little slower to converge.
Ken Felix
PCNSE
NSE
StrongSwan
Hi,
Thank you for the information. I will test and update you by sunday.
One more, for testing this, i need to create one more vpn tunnel in the other end fortinet with my device wan2 ip as a vpn gateway?
Hi,
To test the VPN failover, I created a tunnel between our main site and backup site. I followed the below steps
1.Created two VPN tunnels
2.Created a zone and added the two tunnels
3.Created a static route for the destination subnet with different distances 10 and 20
4. Since we have overlapping subnet in both site we created IP pool and Virtual IP. But the problem is, I am not able to map the virtual IP to the created zone, hence I select interface “any”
5.Created two firewall policies
6. I repeat the same procedure in the backup site
When I disable the wan1 interface of the main site, then the secondary tunnel coming up automatically. But the issue is we not able to reach both end systems subnets. Since we are not able to map the virtual IP to the zone we are facing this issue.
Is there any other option to overcome this? Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.