How to build dual WAN site to site VPN tunnel

Options
Zyxel_Kevin
Zyxel_Kevin Posts: 754  Zyxel Employee
First Anniversary 10 Comments Friend Collector First Answer
edited August 2023 in VPN

Branch office won’t lost access if headquarter primary WAN is dead

Setting

In Headquarter:

Phase1:

My Address: 0.0.0.0

Peer Address: Dynamic Address

Phase2:

Application Scenario: Remote Access (Server Role)

Select server role will force Headquarter respond negotiation only. It is helpful to decrease headquarter loading.

Local Policy: 192.168.0.0/16

In Branch:

Phase1:

My Address: 0.0.0.0

Peer Address: Primary 192.168.168.35, Secondary 192.168.169.35

Select “Fall back to Primary Peer Gateway when possible”

Phase2:

Application Scenario: Remote Access (Client Role)

Select server role will force Headquarter respond negotiation only. It is helpful to decrease headquarter loading.

Local Policy: 10.0.0.0/8

Remote Policy:192.168.0.0/16

Test

Secondary line will take over when Primary is dead.

Then back to Primary when it backs

Note:

To ensure the Tunnel works as expected, we recommend that each Peer uses a single profile and avoids configuring multiple profiles for one Peer.

Tagged: