09-17-2021 06:45 AM
Hello Everyone,
I'm looking at getting the C1116-4P for a branch office. This office will have a layer 2 point to point connection provided by the ISP back to the HQ. One of the ideas being entertained as well is to have a separate Internet connection in addition to this point to point link, incase HQ goes down. My question is, are you able to configure metered routes on the C1116-4P so that if the gateway at HQ becomes unresponsive it switches over to a secondary one, and then switches back when it becomes responsive again?
Also my method of achieving this would be
Router port 1 ----> isp point to point uplink device
Router port 2 ----> FPR1010 connected to standalone internet connection
Configure router to use gateway reachable on port 1 as standard default gateway, will fall back to gateway connected to port 2 if anything goes wrong.
I have the FPR in the mix because I'm not sure if I would be able to do just forwarding with no NAT on one interface, then start NAT'ng everything should the main gateway go down.
If I can make anything clearer let me know. Thank you.
Solved! Go to Solution.
09-17-2021 07:53 AM
Then in that case - you will configure on FTD NAT for the LAN IP to reach internet.
IP route and IP SLA will work.
09-17-2021 07:36 AM
You can use IP sla to track the Link and Fail over to Port2
the question here is on Port2 FTD connected, doe this have already VPN or another means to connect your HQ ?
yes you need NAT (but if FTD already have VPN, they can use VPN to reach HQ ?)
09-17-2021 07:48 AM
A VPN wouldn't be needed in this case as the only time it would switch to the secondary gateway is if HQ goes down, and if they are down then a VPN can't be established anyways. During normal operation there would be no VPN, this is a direct point to point link between the two locations (in the practical sense anyways). The firewall and secondary internet connection would only provide an internet connection in the case of HQ going down, it would provide no other connectivity.
09-17-2021 07:53 AM
Then in that case - you will configure on FTD NAT for the LAN IP to reach internet.
IP route and IP SLA will work.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide