Backup VPN Tunnel

Unanswered Question

I have two data centers and several remote sites connected via EZVpn. For hardware I have two VPN3000s and 2801 routers in the sites. Is there a way to have a fail over ipsec tunnel so that the sites automaticly connect to the second VPNC? Any help would be awesome. I've been looking for docs from Cisco on VPN failover with no luck as of yet.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
John Blakley Fri, 12/05/2008 - 06:32
User Badges:
  • Purple, 4500 points or more

The easiest way is to bring up a tunnel on each router to each VPN concentrator.

On your router, you would have one crypto map that points to multiple peers:

crypt map ACS 5

set peer

set peer


If anything happens on your side, VPN concentrator goes down, then traffic wouldn't be disrupted because the tunnel on the clients end would roll over to the other concentrator.




This Discussion