- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Redundant, policy-based IPsec VPNs
Is there any way to make redundant IPsec VPNs by using policy-based VPNs?
The situation is that customer remote firewall have two links to the Internet and when the main link goes down, there is no commutation of traffic to the now active, backup link, needing to move it's respective policy before the downed policy to keep the traffic going between the locations.
Or just say, a route-based IPsec VPN would be enough?
Thanks!
Vitor
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
+1 for route based.
Create a VPN zone and put both IPSEC interfaces in the zone. You only have to create one set of policies for both VPNs now.
DPD (dead peer detection) is enabled by default, but the default value will only failover after 60 seconds. I'd recommend putting the timers down if you want the failover to happen quicker.
