we currently have ipsec tunnels between our corp office (600c) and various remote satellite offices (40c,60c,90d).
several sites have MPLS back to the corp office instead of ipsec tunnel.
our corp office is the main datacenter, while we have another datacenter that will be setup as failover, and it is 30 miles away, connected via ipsec tunnel. it only has power right now, but in next few months hope to be using it as failover site.
we just started investigating setting up connections between each of the satellite offices. one recommendation we received was instead of routing everything through the corp office 600c, have ipsec tunnels between each satellite office and setup routes and polices accordingly.
but that does not account for failover to the second datacenter.
while researching, I found an article on using quick mode selectors,
http://cookbook.fortinet.com/hub-and-spoke-vpn-using-quick-mode-selectors/
I had never heard of this before, but this looks like a perfect fit for having the second data center, and using a static route so the backup or second datacenter is set to a higher priority number value than the primary datacenter, making it the less preferred route.
is anyone using this setup, and if so, any issues or problems with it?
are there any other options if we are setting up a second datacenter for failover, and want the satellite or spoke sites to be able to roll over to the second site?
OPSF over ipsec VPN is probably what you need to look at. You can run both datacenter active and replicate data between DCs with ease.
ken
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1778 | |
1116 | |
767 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.