Wan fail-over setup with site to site VPN

Posts: 10  Freshman Member
Zyxel Certified Network Administrator - Security First Comment

I have a test setup with dual wan (4 public IPs) and VPN setup with "Primary" and "Secondary". also setting the ip as 0.0.0.0 instead of interface.

My understanding is with this setup wan should fail-over if one goes down.

(Wan trunking is setup up as least load first)

It seems to fail-over but when I ping the other site, it would intermittently "time out" and reconnect for a while, then "time out" again. VPN connection seems unstable after fail-over. I have set icmp check for all connections but its every 5 seconds (for testing), would that be why? or would it be something else?

any input would be greatly appreciated.

Thank you.

Welcome!

It looks like you're new here. If you want to get involved, click on this button!

All Replies

  • Posts: 3,693  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    If you unplug a WAN does it work correctly?

    If one WAN is connected and does ping ok ping fail ping ok then it may think that the interface is ok at times so you may need to set the ping check to be longer or more tolerance

  • Posts: 3,693  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Do you also have routeing rules with ping check? as I have found that interface ping check and routeing ping check for the same WAN interface don't play nice

  • Posts: 10  Freshman Member
    Zyxel Certified Network Administrator - Security First Comment

    Thank you for your reply.

    I changed the load balancing to "Weighted Round Robin" and it kind of stopped timing out.

    now just checking if its the ISP.

    I guess "Least-Load First" does calculations every time it sends out packets, hence the intermittent "time-out"

Welcome!

It looks like you're new here. If you want to get involved, click on this button!

Welcome!

It looks like you're new here. If you want to get involved, click on this button!