Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JohnAgora
Contributor

Redundant VPN

Hello,

 

I have a scenario where a Fortigate has two ISP (one through wan1, another through adsl).

The adsl should only be used in case of wan1 failure.

I see no problem there since I can play with distance and priority.

Anyhow the device should also have 2 VPNs.

The VPN should have an interface associated. Normally it would be wan1.

My problem is what happens with the VPNs when wan1 goes down. I still need traffic to go through a VPN.

The solution I've think is to set up 4 VPNs: 2 with wan1, 2 with adsl.

The issue I have with that solution is that I will have 4 VPNs up all time and that is not the ideal scenario, there should only be two at a time. I've think about unchecking "Keep alive" in the redundant VPN's anyhow I still don't love the solution.

 

Any thoughts?

 

Thanks!

1 REPLY 1
JohnAgora
Contributor

I've done some testing.

My result are:

Even if I configure 4 VPNs and both ISP are available, only 2 VPNs will be up.

When that interface (primary ISP) goes down, the other 2 VPNs goes up.

Someone knows why this happen?

 

I also found the option "set monitor VPN1", anyhow I didn't need to use it.

I think that must be used when you have a redundant VPN in place (different IP for example). Am I right?

 

Thanks!

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors