05-01-2018 09:17 AM - edited 03-12-2019 05:14 AM
I have customer site A & B connecting to Datacenter C &D with same LAN subnet on Customer site A &B.
Datacenter C&D will have site to site VPN tunnel to A&B. I have enabled RRI in the Datacenter firewalls.In essence both the datacenters will learn the same remote network and redistribute this network into IGP thus creating a routing conflict for all the remote sites which try to connect to the remote network.
As you know RRI will always insert a static route irrespective of the tunnel status.
I would like the remote location to always go through Data center C Site to site VPN tunnel and use Data center D in case of any issues with VPN tunnel on "C" side.
Is there a way I can achieve VPN redundancy using this scenario.Please help me with this.
Note:- customer is not agreeing for Natting the network on their side.
05-01-2018 09:23 PM
Hi
I believe you've configured nat for your vpn as you've 2 remote sites with overlapping subnets.
If you use the crypto map command set peer IP1 IP2, it's gonna do what you're expecting.
This command build up a vpn with IP1 And switch over IP2 when IP1 isn't reachable.
05-02-2018 03:19 AM
05-02-2018 06:37 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide