double fail-over WAN and VPN
Hello,
We have 2 sites connected with VPN, ATP units on both locations.
Each site has 2 ISP connected for fail over, and fail over configured Trunk - LeastLoad First, Inbound+Outbound. Second ISP in passive.
I would like to have VPN working, no matter which provider fails.
What is the best way to realize that?
I saw this article
How to Use Dual-WAN to Perform Fail-Over on VPN Using the VPN Concentrator – Zyxel Support Campus EMEA
In my case, when only 2 sites, and not 3, do i need to configure a concentrator or is adding Secondary IPs to VPN Gateway setup(on both ends) is enough?
Thank you
We have 2 sites connected with VPN, ATP units on both locations.
Each site has 2 ISP connected for fail over, and fail over configured Trunk - LeastLoad First, Inbound+Outbound. Second ISP in passive.
I would like to have VPN working, no matter which provider fails.
What is the best way to realize that?
I saw this article
How to Use Dual-WAN to Perform Fail-Over on VPN Using the VPN Concentrator – Zyxel Support Campus EMEA
In my case, when only 2 sites, and not 3, do i need to configure a concentrator or is adding Secondary IPs to VPN Gateway setup(on both ends) is enough?
Thank you
0
Best Answers
-
Hi @Orad,You can find the topic "How to Create VTI and Configure VPN Failover with VTI" in the handbook.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Hi @Orad,In this example, only two VPN Gateway are configured on each device:HQ_wan1------BO_wan1HQ_wan2------BO_wan2If you need full redundancy in case HQ_wan1 and BO_wan2 are disconnected at the same time, you need to add extra two VPN Gateways, corresponding VPN tunnels and extra two VTI interfaces.HQ_wan1------BO_wan2HQ_wan2------BO_wan1
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0
All Replies
-
Hi @Orad,You can find the topic "How to Create VTI and Configure VPN Failover with VTI" in the handbook.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
thank you @Zyxel_Emily
In handbook they create 2 VTIs, but if i understand correctly, i would need 4 VTIs on each side to get "full" redundancy?0 -
Hi @Orad,In this example, only two VPN Gateway are configured on each device:HQ_wan1------BO_wan1HQ_wan2------BO_wan2If you need full redundancy in case HQ_wan1 and BO_wan2 are disconnected at the same time, you need to add extra two VPN Gateways, corresponding VPN tunnels and extra two VTI interfaces.HQ_wan1------BO_wan2HQ_wan2------BO_wan1
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
@Zyxel_Emily
also, we tested it today and it does work, but time it takes to reconnect VPN is a bit longer than we expected. Which settings should i play with to control it?
it took about a 4-5 minutes before tunnel connected.
In trunk i have it set to Least Load First/Outbound. Should i change it to Spillover?0 -
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 148 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight