cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
680
Views
0
Helpful
1
Replies

VPN IPsec High availability

noeperezs
Level 1
Level 1

Hi, I have a branch router with IPsec configuration pointing to three central peers for backup with the same interesting traffic; the network is MPLS.

I configure DPD and when the first peer is down, the branch router established a new IPsec tunel to the second peer.

The problem is when the first router is up again; the tunel to the second peer is up and the branch is not able to reach applications.

is there a way to clear dinamically or automatically (not manual clear) the tunel to the second router and establish a new tunel to the first peer?

TIA

1 Reply 1

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Noe,

You have not provided too much info. So what I would say evaluate either:

- GET VPN which was deisigned to, among others, work over MPLS networks

- Move to a logical interface solution : GRE over IPsec, VTI, DMVPN, Flex, whichever you want and run routing protocol over that network.

- Preferred peer maybe? Depends on your corruent setup.

In anyway I suggest you have a look at mechanisms built into protocol itself:

http://www.cisco.com/en/US/docs/ios/sec_secure_connectivity/configuration/guide/sec_rev_rte_inject_ps10591_TSD_Products_Configuration_Guide_Chapter.html

HTH,

Marcin