cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
433
Views
0
Helpful
0
Replies

IPSec Tunnel Drops During Link Failover – How Do You Handle It?

Hi Cisco Community,

One common issue I’ve faced is IPSec tunnels dropping or flapping during WAN failover. Sometimes Dead Peer Detection (DPD) timers kick in too late, or NAT-T creates problems.

My questions to the community are:

  1. What parameters (timers, keepalives) do you normally adjust for stable failover?
  2. Do you prefer static routes or dynamic routing (BGP/OSPF) across the tunnels?
  3. Any Cisco guides or design best practices you recommend for stable IPSec under failover?

Thanks,

0 Replies 0