Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ddpf
New Contributor

Redundant IPsec VPN Design Recommandation

Hi there

I need your advice on what is the best IPsec design for our setup.

We have one HQ with dual ISP's and 14 other sites with single ISP.

Now my question is should I implement it, via static routes like here Technical Tip: Redundant IPSEC Tunnel using single WAN connection , IPSEC Aggregate or something else?

 

(Fortigate v7.4.9 build2829)

Thanks for your recommendation and have a nice day.

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi

The shared tech tip is a good approach.

However using sd-wan is definitely the most flexible, effective and modern approach so far.

https://community.fortinet.com/t5/Support-Forum/How-to-Configure-Redundant-IPsec-Tunnels-over-SD-WAN...

AEK
AEK
Toshi_Esumi
SuperUser
SuperUser

More traditional option is like using BGP to make one side primary and the other side a backup.

 

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors