Setting up Site-to-Site VPN with multiple wan IP on both sides




I see the primary and secondary Peer Gateway address, which would be for the other site but what if "My address" also has 2 IP's for load balancing/failover?
I think if I was to select wan 1 or wan 2, it would not failover correctly when one of the link is down.
any help would be appreciated.
Thank you.
All Replies
-
Hi @HyungKim0105,
You may consider setting up DDNS for this requirement. In addition, the Nebula firewall supports auto-selecting the VPN outgoing interface.
After setting up, the Nebula control center will provide you with a domain to connect.
Zyxel Melen0 -
Thank you for your reply.
If I didnt want to go through the DDNS route, would setting up multiple site-to-site ipsec solve the problem?
example - site 1 has ip 1.1.1.1 and 3.3.3.3. site 2 has ip 2.2.2.2 and 4.4.4.4.
setup site to site 1.1.1.1 to 2.2.2.2 and 4.4.4.4.
also set up 3.3.3.3 to 2.2.2.2 and 4.4.4.4.
would this also work?
Thank you.
0 -
Hi @HyungKim0105,
If you're using the USG FLEX/ATP series, please reference these information:
- How to build dual WAN site to site VPN tunnel — Zyxel Community
- USG FLEX/ATP User's Guide P220 How to Configure IPSec VPN Failover
Hope it helps.
Zyxel Melen0
Categories
- All Categories
- 429 Beta Program
- 2.6K Nebula
- 163 Nebula Ideas
- 112 Nebula Status and Incidents
- 6K Security
- 350 USG FLEX H Series
- 291 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 261 Service & License
- 406 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.8K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 82 Security Highlight