USG 110 - VPN Site to Site with Dual Wan issue

Options
Paul_FR
Paul_FR Posts: 4
Friend Collector First Comment
edited April 2021 in Security
Hi everybody,

I am working on install a VPN site to site with routeur USG Series.

The HQ has a USG110 with dual WAN, and the Branch has a USG40.

Firmware :
USG110 -   V4.39(AAPH.0)
USG40 - V4.39(AALA.0)



Here are the settings for the VPN Ipsec :
HQ :
VPN Gateway :

VPN Connection

Branch :
VPN Gateway :

VPN Connection :


My issue is that the VPN mount on WAN1, but if WAN1 fail it doesn't mount on WAN2.

Here are the logs from the USG40.
VPN - BRANCH to WAN1 HQ :

VPN - BRANCH to WAN2 HQ :


If i change the VPN Gateway on the HQ's USG110 :

The VPN mount well.


Could someone tell me why the VPN doesn't mount on WAN2 in case of failure of WAN1?
Did i do something wrong in my settings?

Accepted Solution

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,366  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options

    Hi @Paul_FR  

    You can try to configure My Address as 0.0.0.0 in VPN Gateway.

    It means all of interfaces could be VPN Gateway, but not only specific one.

    Then branch should able to establish VPN tunnel when HQ WAN1 is dead.



All Replies

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,366  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options

    Hi @Paul_FR  

    You can try to configure My Address as 0.0.0.0 in VPN Gateway.

    It means all of interfaces could be VPN Gateway, but not only specific one.

    Then branch should able to establish VPN tunnel when HQ WAN1 is dead.



  • Paul_FR
    Options
    Hi @Zyxel_Stanley,

    Thank you that work!

Security Highlight