How to build dual WAN site to site VPN tunnel

Zyxel_Kevin
Zyxel_Kevin Posts: 855  Zyxel Employee
100 Answers Second Anniversary 500 Comments Zyxel Certified Sales Associate
edited August 2023 in VPN

Branch office won’t lost access if headquarter primary WAN is dead

Setting

In Headquarter:

Phase1:

My Address: 0.0.0.0

Peer Address: Dynamic Address

Phase2:

Application Scenario: Remote Access (Server Role)

Select server role will force Headquarter respond negotiation only. It is helpful to decrease headquarter loading.

Local Policy: 192.168.0.0/16

In Branch:

Phase1:

My Address: 0.0.0.0

Peer Address: Primary 192.168.168.35, Secondary 192.168.169.35

Select “Fall back to Primary Peer Gateway when possible”

Phase2:

Application Scenario: Remote Access (Client Role)

Select server role will force Headquarter respond negotiation only. It is helpful to decrease headquarter loading.

Local Policy: 10.0.0.0/8

Remote Policy:192.168.0.0/16

Test

Secondary line will take over when Primary is dead.

Then back to Primary when it backs

Note:

To ensure the Tunnel works as expected, we recommend that each Peer uses a single profile and avoids configuring multiple profiles for one Peer.

Tagged: