Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
vstrabello
New Contributor

Redundant, policy-based IPsec VPNs

Is there any way to make redundant IPsec VPNs by using policy-based VPNs?

 

The situation is that customer remote firewall have two links to the Internet and when the main link goes down, there is no commutation of traffic to the now active, backup link, needing to move it's respective policy before the downed policy to keep the traffic going between the locations.

 

Or just say, a route-based IPsec VPN would be enough?

 

Thanks!

 

Vitor

2 REPLIES 2
EMES
Contributor

Route based all the way.
neonbit
Valued Contributor

+1 for route based.

 

Create a VPN zone and put both IPSEC interfaces in the zone. You only have to create one set of policies for both VPNs now.

 

DPD (dead peer detection) is enabled by default, but the default value will only failover after 60 seconds. I'd recommend putting the timers down if you want the failover to happen quicker.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors