IPSec stateful failover on IOS routers

Unanswered Question
Feb 5th, 2009
User Badges:
  • Silver, 250 points or more

Need advice from VPN experts in this forum who actually have done

something similar to this:

Current Configuration:

a Single VXR7206 with VAM+2 card for site-2-site VPN. There are

about 10 VPN tunnels on this device. Remote VPN peers range from

Checkpoint Firewall/VPN, Juniper, SonicWall, IOS routers and ASA

appliances. There are about 4 GRE/IPSec tunnels and the remaining

VPN tunnels are standard site-2-site VPNs.


Increase redundancy capability by adding another VXR7206 router to

allow for IPSec stateful failover. Must be able to accomodate ALL

remote VPN peers such as Checkpoint, Juniper, SonicWall, IOS routers

and ASA appliances.

Question: What is the best approach to this?

Many thanks.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)


This Discussion