03-19-2019 10:38 PM
Hi everyone,
I would like to get a expert advice on Cisco ASA site to site VPN tunnel failover between two different site firewall.
I know vpn- loadbalancing is used for remote access VPN users with 2 ASA configured for load balancing and in case of failure the remaining ASA serve for all anyconnect client with itsi capacity.
But How to design or use site to site VPN failover if a tunel fails for a particular local and remote network, and how the failover scenario looks??
Do we need 4 firewall with 2 each at different side ?
Or with single firewall with 2 different isp each side?
Can anyone please explain how it could be achievable?
Thank you in advance.
03-20-2019 12:37 AM
You can do the single ASA or Dual ASA for high resiliance based on the business requirement.
You configure both the tunnels (so the tunnels will be up), then you do failover with IP SLA Tracking.
03-20-2019 03:09 AM
03-20-2019 04:57 AM
03-20-2019 05:13 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide