How to implement failover on VPN connection ?

Piroux
Piroux I dont want to receive any newsletter Posts: 1 image  Freshman Member

Hello,

I want to set up a failover between two VPN connections, so when one of them fails, I switch automatically to the second one. I tested the use of VTI with a dedicated trunk. It worked once, but I saw that I had to create new firewall rules for the subnet that tests the connection between remote VTI interfaces.

I also tested the configuration of two remote gateways on the VPN gateway. The connection is active but when I disconnect an interface, the switch does not work. I think it comes from the fixed interface defined.

Are these the right solutions? Or is there something more strategic to implement?

All Replies

  • Zyxel_Melen
    Zyxel_Melen Business and consumer products Posts: 3,876 image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Piroux

    Since it is vague of your question, could you please specific your model and the type of VPN? It helps us to understand your issue before providing a solutiona or workaround for you.

    Zyxel Melen


  • jasperwilde09
    jasperwilde09 Business products Posts: 1 image  Freshman Member
    First Comment First Anniversary

    Hi everyone,

    I’m also interested in this topic because I’ve been trying to set up VPN failover too. In my case, I noticed the same issue where the connection doesn’t automatically switch when one interface goes down.

    Could anyone share if there’s a recommended method (like using SD-WAN, VPN trunk, or another approach) to make the failover more seamless?

    Thanks!

  • Zyxel_Melen
    Zyxel_Melen Business and consumer products Posts: 3,876 image  Guru Member
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @jasperwilde09

    Try to setup DDNS for your firewall and use this DDNS in your VPN configuration.

    Zyxel Melen