cancelar
Mostrar resultados para 
Pesquisar em vez de 
Queria dizer: 
cancel
918
Apresentações
0
Útil
1
Respostas

two IPSec VPN to same site with different ISPs?

KleberMuniz
Level 1
Level 1

Hello Guys!

Someone, can help me with this scenario? Google this time was not enough...

Primary link is R1 -> R3 -> R2

NAT failover working perfect thanks to ip sla and track

VPN site-to-site working ok through primary link.

When R3 goes down, all traffic switch to R4 but VPN seems to freeze.

The session status are UP-ACTIVE on both routers.

VPN Site-to-Site.jpeg.jpeg

R1#sh cry session

Crypto session current status

Interface: Serial0/1

Session status: UP-ACTIVE

Peer: 20.20.20.1 port 500

  IKE SA: local 10.10.10.1/500 remote 20.20.20.1/500 Active

  IPSEC FLOW: permit ip 192.168.10.0/255.255.255.0 192.168.20.0/255.255.255.0

        Active SAs: 2, origin: crypto map

Interface: Serial0/2

Session status: UP-ACTIVE

Peer: 40.40.40.1 port 500

  IKE SA: local 30.30.30.1/500 remote 40.40.40.1/500 Active

  IPSEC FLOW: permit ip 192.168.10.0/255.255.255.0 192.168.20.0/255.255.255.0

        Active SAs: 2, origin: crypto map

THANKS!

1 RESPOSTA 1

Gustavo Medina
Cisco Employee
Cisco Employee

Hi,

Can you share your configs? Did you set up keepalives? You might want to take a look at this discussion.

https://supportforums.cisco.com/message/3370354#3370354

Regards,