When policy route is used for failover IP-Sec tunnels die. Why?
Hi,
I am a lucky guy! I have two fiber hookups to the internet. One is 500M/bit, te second 100M/bit. I would like to use the 500 as the main pipe and the 100 as a failover.
Therefor I have created two policy routes where if the 500 (Ge3) fials, the 100 (Ge2) takes over. In theory this works fine as I also changed the trunk to spill-over (user configured). When I activate the policy routes my IP-Sec VPN tunnels die however.
I have been looking if I can find a way to leave the tunnels up and running but cannot find a way.
What can be the problem?
All Replies
-
Hi @JeroenSoree
Regarding to the topology you deployed, it’s our suggestion that you can implement VTI to achieve the purpose.
VTI VPN Tunnel Interface is used to configure IPSec-based VPNs between site-to-site devices.
VTI is similar to other physical interfaces so that policy route, static route and trunk can be applied when the tunnel is activated.
Here is the FAQ of how to setup IPSec site-to-site VPN by using VTI on the USG .
Don't miss this great chance to upgrade your Nebula org. for free!
1
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 130 Nebula Ideas
- 90 Nebula Status and Incidents
- 5.4K Security
- 171 USG FLEX H Series
- 256 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 235 Service & License
- 372 News and Release
- 77 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight