USG 110 - VPN Site to Site with Dual Wan issue

Paul_FR
Paul_FR Posts: 4
First Comment Friend Collector
edited April 2021 in Security
Hi everybody,

I am working on install a VPN site to site with routeur USG Series.

The HQ has a USG110 with dual WAN, and the Branch has a USG40.

Firmware :
USG110 -   V4.39(AAPH.0)
USG40 - V4.39(AALA.0)



Here are the settings for the VPN Ipsec :
HQ :
VPN Gateway :

VPN Connection

Branch :
VPN Gateway :

VPN Connection :


My issue is that the VPN mount on WAN1, but if WAN1 fail it doesn't mount on WAN2.

Here are the logs from the USG40.
VPN - BRANCH to WAN1 HQ :

VPN - BRANCH to WAN2 HQ :


If i change the VPN Gateway on the HQ's USG110 :

The VPN mount well.


Could someone tell me why the VPN doesn't mount on WAN2 in case of failure of WAN1?
Did i do something wrong in my settings?

Accepted Solution

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,377  Zyxel Employee
    100 Answers 1000 Comments Friend Collector Seventh Anniversary
    Answer ✓

    Hi @Paul_FR  

    You can try to configure My Address as 0.0.0.0 in VPN Gateway.

    It means all of interfaces could be VPN Gateway, but not only specific one.

    Then branch should able to establish VPN tunnel when HQ WAN1 is dead.



All Replies

  • Zyxel_Stanley
    Zyxel_Stanley Posts: 1,377  Zyxel Employee
    100 Answers 1000 Comments Friend Collector Seventh Anniversary
    Answer ✓

    Hi @Paul_FR  

    You can try to configure My Address as 0.0.0.0 in VPN Gateway.

    It means all of interfaces could be VPN Gateway, but not only specific one.

    Then branch should able to establish VPN tunnel when HQ WAN1 is dead.



  • Hi @Zyxel_Stanley,

    Thank you that work!

Security Highlight