<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN High-Availability in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-high-availability/m-p/1239330#M954400</link>
    <description>&lt;P&gt;Head office with one Router (2851) connected to the LAN and several site-to-site VPN on the outside Ethernet to the branche offices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to improve a kind of High-Availability ONLY on the head office.&lt;/P&gt;&lt;P&gt;I added a second Routers (2811) connected with HSRP to the LAN.&lt;/P&gt;&lt;P&gt;I tryed to implement HSRP also on the outside, but the VPNs dont go UP to the "virtual" IP of the HSRP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way?&lt;/P&gt;&lt;P&gt;- double VPN, one to each Router - but how to decide priority?&lt;/P&gt;&lt;P&gt;- gre tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank's&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:26:18 GMT</pubDate>
    <dc:creator>battanc</dc:creator>
    <dc:date>2020-02-21T11:26:18Z</dc:date>
    <item>
      <title>VPN High-Availability</title>
      <link>https://community.cisco.com/t5/network-security/vpn-high-availability/m-p/1239330#M954400</link>
      <description>&lt;P&gt;Head office with one Router (2851) connected to the LAN and several site-to-site VPN on the outside Ethernet to the branche offices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to improve a kind of High-Availability ONLY on the head office.&lt;/P&gt;&lt;P&gt;I added a second Routers (2811) connected with HSRP to the LAN.&lt;/P&gt;&lt;P&gt;I tryed to implement HSRP also on the outside, but the VPNs dont go UP to the "virtual" IP of the HSRP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way?&lt;/P&gt;&lt;P&gt;- double VPN, one to each Router - but how to decide priority?&lt;/P&gt;&lt;P&gt;- gre tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank's&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-high-availability/m-p/1239330#M954400</guid>
      <dc:creator>battanc</dc:creator>
      <dc:date>2020-02-21T11:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN High-Availability</title>
      <link>https://community.cisco.com/t5/network-security/vpn-high-availability/m-p/1239331#M954401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;did you try this guide (HSRP+ SSO+IPSEC VPN) ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_3t/12_3t11/feature/guide/gt_topht.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_3t/12_3t11/feature/guide/gt_topht.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 May 2009 12:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-high-availability/m-p/1239331#M954401</guid>
      <dc:creator>mdombek_biz</dc:creator>
      <dc:date>2009-05-05T12:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN High-Availability</title>
      <link>https://community.cisco.com/t5/network-security/vpn-high-availability/m-p/1239332#M954402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest "double VPN, one to each Router".  As to deciding priority, depends on whether you see any advantage to off-loading some of the existing 2851 VPN load to the new 2811.  Probably simpler to make 2851 primary path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unsure about your question about GRE tunnels.  If you're doing VPN without them, GRE tunnels support traffic that something like native IPSec might not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 16:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-high-availability/m-p/1239332#M954402</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2009-05-11T16:52:16Z</dc:date>
    </item>
  </channel>
</rss>

