cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1179
Views
0
Helpful
1
Replies

Site-site vpn tunnel with failover using GLBP instead of HSRP : not working

vinodjad1234
Level 2
Level 2

Hi,

i'm  already using  a site to site VPN tunnel from all the branches to my DC  routers with failover using HSRP. All branches destination is HSRP VIP  configured on my DC routers which is working fine. Here in this set-up  only one router is actively utilized. Is there any possibilities to  utilize both of my DC routers actively to achieve load sharing using  GLBP?

We  tried configuring the same using GLBP where we are unable to bind the  crypto map "map name" redundancy "group name" under the GLBP configured  interface, it gives "%ip redundancy is not configured on this interface"  error. Please suggest, if any one has already configured this kind of  set-up.

Regards,

Vinod.

1 Reply 1

jan.nielsen
Level 7
Level 7

Using a virtual ip to terminate ipsec on, is af ar as i know only supported on the actual interface ip or hsrp vip, not anything else. Are you using DMVPN or legacy ipsec L2L ? With DMVPN, you could have your routing protocol handle load balancing