cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
591
Views
0
Helpful
3
Replies

Redundant VPN

jrgates
Level 1
Level 1

We have a few site to site VPN connections with 5505's. Is there any way to setup a redundant config incase the first one goes down it would reestablish to a second firewall with a different ISP? I am using 5520's at both ISP's.

3 Replies 3

naveen_b81
Level 1
Level 1

You can create two peers for the VPN tunnels. But this will not solve your problem completely as the internal routing needs to be changed to the second pix when the first one fails. For options on changing the internal routing, we will need to know your setup better

Thanks for the reply. Couldn't I just do a weighted route?

You should be taking care of the routing part seperately. A weighted route will not work with PIX/ASA as the ethernet link will never go down unless the other end device goes down. However, you can track the link (reachability of the vpn peer) and map it to a route.

Check the below link for configuration details

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

Review Cisco Networking for a $25 gift card