12-07-2017 11:49 AM - edited 03-12-2019 04:48 AM
Hi Guys,
We currently have 2 Datacenters, but for management we only have 1 AnyConnect entry. Now we're looking into bringing in some redundancy for our AnyConnect VPN and we found the Backup Server. Now i might be missing something here, but i coulnd't really find the explanation of how this function works.
Basically, what we are looking for is keeping the current AnyConnect entry, but when that one fails it should use the ASA in the other Datacenter. I was just wondering how traffic would flow using the Backup Server function. And do i have to create all my rules i currently have in the 1st Datacenter also in the 2nd Datacenter?
12-08-2017 06:42 AM
The function is pretty straightforward, if the primary address is not reachable it will try to connect to the the backup vpn servers configured.
The backup vpn can have a different configuration, but you probably want to have the same authentication and access to devices as the primary vpn, so you should have the same rules as in 1st DC.
IP addresses assigned to VPN clients should be different in order to be able to route them.
12-09-2017 04:30 AM
Ah, i see. So even though you define it as a Backup Server, the Backup Server itself needs to be completely configured as a AnyConnect VPN server, right?
12-09-2017 02:37 PM
Corect.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide