<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN failover  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100291#M878383</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Active/Active is supported for SSL VPN &lt;/P&gt;&lt;P&gt;termination.  Active/Active is NOT supported&lt;/P&gt;&lt;P&gt;for L2L VPN or remote access VPN.    &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Jan 2009 20:06:15 GMT</pubDate>
    <dc:creator>cisco24x7</dc:creator>
    <dc:date>2009-01-05T20:06:15Z</dc:date>
    <item>
      <title>VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100288#M878380</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have below setup for the our network &lt;/P&gt;&lt;P&gt;  SITE A                  SITE B&lt;/P&gt;&lt;P&gt;  |                        |VPN&lt;/P&gt;&lt;P&gt;  |VPN                     |&lt;/P&gt;&lt;P&gt;  ISP 1                   ISP 2&lt;/P&gt;&lt;P&gt;   |                        |&lt;/P&gt;&lt;P&gt;  R1                       R2&lt;/P&gt;&lt;P&gt;   |                        |&lt;/P&gt;&lt;P&gt;  FW                       FW&lt;/P&gt;&lt;P&gt;-----------------------------------------&lt;/P&gt;&lt;P&gt;          lan subnet 192.168.1.0 /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need a failover for the vpn Connection from our LAN subnet pls suggest me some deployment ideds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100288#M878380</guid>
      <dc:creator>vinoth.kumar</dc:creator>
      <dc:date>2019-03-11T14:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100289#M878381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's a good book that covers multiple redundant designs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.amazon.com/IPSec-VPN-Design-Networking-Technology/dp/1587051117/ref=pd_bbs_sr_3?ie=UTF8&amp;amp;s=books&amp;amp;qid=1230561369&amp;amp;sr=8-3" target="_blank"&gt;http://www.amazon.com/IPSec-VPN-Design-Networking-Technology/dp/1587051117/ref=pd_bbs_sr_3?ie=UTF8&amp;amp;s=books&amp;amp;qid=1230561369&amp;amp;sr=8-3&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Dec 2008 14:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100289#M878381</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-12-29T14:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100290#M878382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was just reading about active/active failover on cco and it says that vpn is not supported by active/active failover.  You'll need to concentrate on active/standby failover.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jan 2009 19:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100290#M878382</guid>
      <dc:creator>cchughes</dc:creator>
      <dc:date>2009-01-05T19:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100291#M878383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Active/Active is supported for SSL VPN &lt;/P&gt;&lt;P&gt;termination.  Active/Active is NOT supported&lt;/P&gt;&lt;P&gt;for L2L VPN or remote access VPN.    &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jan 2009 20:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100291#M878383</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-01-05T20:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100292#M878384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok fine from my lan that is 192.168.151.0/24 if i need to reach remote destination through VPN 10.254.254.1/24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;consider we have two internet link that is A and B from both the link we have established VPN to Remote PEER that is X allowing the remote private ip subnet 10.254.254.1/24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is how i can automatically redirect the traffic to reach my destination private network if one link goes down to other link &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vinoth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2009 07:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100292#M878384</guid>
      <dc:creator>vinoth.kumar</dc:creator>
      <dc:date>2009-01-07T07:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100293#M878385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same requirement.  I'm seeing that I need to go active/standby to accomplish this.  I'd prefer to go active/active so I'll be watching and updating this thread as I progress.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone knows of a trick to support site-site vpn in an active/active mode please inform us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2009 17:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100293#M878385</guid>
      <dc:creator>cchughes</dc:creator>
      <dc:date>2009-01-07T17:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100294#M878386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to understand this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Active/Active is very mis-leading.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Active/Active in cisco means that it will &lt;/P&gt;&lt;P&gt;load-sharing traffics for different sources,&lt;/P&gt;&lt;P&gt;not the same source.  For example, let say&lt;/P&gt;&lt;P&gt;you want to send a 50Mbps stream from source X&lt;/P&gt;&lt;P&gt;to source Y.  You want to split 50mbps between&lt;/P&gt;&lt;P&gt;PixA and PixB.  That is not possible in &lt;/P&gt;&lt;P&gt;cisco Active/Active mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know of a trick to support s2s vpn in &lt;/P&gt;&lt;P&gt;Active/active mode; however, I know that &lt;/P&gt;&lt;P&gt;checkpoint can do this since 2003 and I am &lt;/P&gt;&lt;P&gt;using it now as we speak.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2009 18:14:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100294#M878386</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-01-07T18:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100295#M878387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Understood.  When i say "tricks" I was thinking of techniques or architectures that would allow me to utilize both ASA's and not having one in standby.  Since ipsec vpn is not supported at all in active/active, I'm considering using a router behind the ASA's to terminate the tunnels and allow the tunnel thru the ASA's.  The problem i see with that is single point of failure.  Still searching...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jan 2009 18:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100295#M878387</guid>
      <dc:creator>cchughes</dc:creator>
      <dc:date>2009-01-07T18:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN failover</title>
      <link>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100296#M878388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But iam not clear on above point &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i am asking is i have a peer X which is sonic wall firewall connected with the two ISP link for example A and B &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They need reduanacy for the peer Y which is my PIX firewall through VPN in active /standby mode &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible from my PIX firewall to have two Peer IP for the same crypto map in active/standby &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;vinu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jan 2009 15:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-failover/m-p/1100296#M878388</guid>
      <dc:creator>vinoth.kumar</dc:creator>
      <dc:date>2009-01-19T15:59:55Z</dc:date>
    </item>
  </channel>
</rss>

