02-26-2009 10:06 AM - edited 02-21-2020 03:19 AM
We have a few site to site VPN connections with 5505's. Is there any way to setup a redundant config incase the first one goes down it would reestablish to a second firewall with a different ISP? I am using 5520's at both ISP's.
02-26-2009 11:09 PM
You can create two peers for the VPN tunnels. But this will not solve your problem completely as the internal routing needs to be changed to the second pix when the first one fails. For options on changing the internal routing, we will need to know your setup better
02-27-2009 05:41 AM
Thanks for the reply. Couldn't I just do a weighted route?
03-04-2009 01:39 AM
You should be taking care of the routing part seperately. A weighted route will not work with PIX/ASA as the ethernet link will never go down unless the other end device goes down. However, you can track the link (reachability of the vpn peer) and map it to a route.
Check the below link for configuration details
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide