cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1102
Views
0
Helpful
5
Replies

Fault tolerant IPSec tunnels (Failover)

IT Services
Level 1
Level 1

Good Morning,

We have multiple Site-to-Site IPSec tunnels created. Currently we are using 2 ISP Links and bonding them using a Peplink Balance 380.  We have this configuration at multiple sites. Currently if the ISP connection (which is where our peer IP is configured) drops the secondary ISP will take the session over which causes the tunnels to drop. Is there a way we could have the tunnels re-initialize on the other ISP network in this scenario?

Any suggestions?                  

5 Replies 5

Hi

Please check this out and let me know if you have any questions.

https://supportforums.cisco.com/thread/2162274

Thanks.

Rate any post you find helpful.

This looks good, but my question would be since we have load balancing setup on the Peplink WAN bonding router, would this change the configuration at atll?

Does your ASA have two Internet connections?

Thanks.

Here is our topology:

ISP 1  ------> WAN 1 (Peplink)

ISP 2  ------> WAN 2 (Peplink)

LAN1 X.X.X.X (ISP 1 Network) (Peplink) ------> Eth 0/0 (Outside) ASA - X.X.X.X (ISP 1 Network)

Then the configuration is the same.

Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: