01-11-2006 06:10 AM - edited 02-21-2020 02:11 PM
I have 2 Different ISP links on whihc I need to run VPN and want the links to be in redundancy. Limitation are there but any design work around that you people can suggest.
01-11-2006 05:21 PM
Hello,
network design means also to pay attention to any restriction/limitation. Can you shed some light on the topology you have, the equipment involved and the "limitations" mentioned?
Thanks in advance
Martin
01-12-2006 03:33 AM
Dear Martin,
Thanks for your response. I have PIX with 7.0.4 version and 2 ISP links.I have VPN connectivity between 2 offices over IPSEC.My US office is stable but India end links fluctuate so in India I have 2 ISP and required to make them redundant. Previously I have one ISP link so it was working fine.
But now with 2-ISP I can't understand the design how to load balace VPN on that.
If you required any other info. plz reight back to me.
Thanks
Gaurav
01-12-2006 02:31 PM
Hi there,
For this to work, you'll need more equipment in the design (the PIX itself can't have two default gateways):
Option A)
1) Put in another PIX on ISP link #2
2) Enable OSPF routing over the IPsec links
3) Let your internal LAN router on the India-side talk OSPF with the PIX'es as well. If you don't have a LAN-router, you'll need another interface on the PIX'es to allow for forwarding the packets to the other PIX. Or juts inside&outside on the extra PIX, while you add another interface on the old one.. or the other way around.. you choose. :)
Option B)
1) Put a router in front of the PIX and let the ISP connections go to this router.
2) Do some bidirectional NAT'ing on the router to let the connections be 'stateful'
Did it help? If so, please rate it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide