cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
307
Views
0
Helpful
2
Replies

IOS to IOS IPSec tunnel - configuring an alternate peer

crhodes
Level 1
Level 1

Hello,

I am setting up an environment where remote IOS based IPSec peers establish tunnels to a central IOS based IPSec peer. (both running 12.2(13)T)

Is there a way the remote peer can be configured to attempt to establish a tunnel with an alternate peer (different IP address) if the preferred peer is unavailable?

Thanks in advance.

2 Replies 2

jfrahim
Level 5
Level 5

Hi there,

Under the crypto map, make sure that you add you set peer statements. The first set peer should be your primary peer, and the second one should be your secondary peer

Hope that helps

Jazib

Philip D'Ath
VIP Alumni
VIP Alumni

Another way is to run IPSec between just the two external IP interfaces. Then run GRE over this, and a dynamic routing protocol, like EIGRP.