Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ohadfaibish
New Contributor

VPN connection to DC and DR

Hello,

I'm looking for solution that we have a s2s VPN connection between site A to our DC

We want to add a DR on OCI ( oracle cloud) and want to connect it also by s2s VPN and to make this connection as backup.

If the connection/FW on DC side will go down the VPN will change to the DR and if the connection will go up again in the DC it will go back.

Adding a visio 

What is the best way to make it happened? 

1 Solution
sw2090
Honored Contributor

We have it here this way with 21 shop Sites.

Each has two S2S IPsec to HQ and redundncy is made by redundant routes with different prio/distance.

Primarily traffic behaves like electric current - it always takes the way of the lowest cost per default.

So it will take the S2S with lowest routig prio/distance if available. If that is not available it will take the S2S with the next highest routing prio/distance until the other is back available.

Works fine here.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

View solution in original post

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
11 REPLIES 11
sw2090
Honored Contributor

why shouldn't that work. The only difference is that only one S2S goes to your side and the other to the cloud. Makes absolutely no difference for routing.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
ohadfaibish

Perfect! Thank you very much for the help and the time.

 

Take care and be safe!

Labels
Top Kudoed Authors