10-31-2019 01:58 AM - edited 10-31-2019 01:59 AM
Hi team,
I want to know how to configure Active Standby site to site VPN. Not with 2 firepower in HA pair but 2 internet link in one firepower. With this 2 internet link one is primary with default route of metric 1 and the other is backup with metric 2. While i configure this only one VPN is up (with primary internet) and the other one is not. So would you all en light me on how to configure that. Notice that i use Firepower Management Center. Also, you can find the scenario in below picture.
10-31-2019 02:30 AM
I would suggest configuring SLA tracking of the primary link and not just use metic.
The second VPN tunnel will never be up unless there is traffic passing over the VPN. If there is no traffic the tunnel will time out and be torn down. Only true way of testing this is to initiate a failover situation, i.e. link failure on the primary interface for the VPN.
10-31-2019 02:36 AM - edited 10-31-2019 02:37 AM
Yes i have done the SLA and also try to do the failover by disable the primary link but the second VPN tunnel never goes up. Also, it is difficult to see the log on firepower management center so i have no idea on what the error.
10-31-2019 02:42 AM
Just disabling the link will not initiate a failover as that is a controlled / admin initiated command. You will need to pull the cable connected to the primary interface.
10-31-2019 02:46 AM
10-31-2019 03:51 AM
Sorry, misread your post that you had configured SLA.
How have you configured your VPN? Are you using a backup peer or configured a whole new connection for the backup? Could you post screenshots of your VPN configuration (remember to black-out any public IPs, passwords, etc.)?
10-31-2019 05:41 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide