Redundant VPN

Unanswered Question
naveen_b81 Thu, 02/26/2009 - 23:09
User Badges:

You can create two peers for the VPN tunnels. But this will not solve your problem completely as the internal routing needs to be changed to the second pix when the first one fails. For options on changing the internal routing, we will need to know your setup better

naveen_b81 Wed, 03/04/2009 - 01:39
User Badges:

You should be taking care of the routing part seperately. A weighted route will not work with PIX/ASA as the ethernet link will never go down unless the other end device goes down. However, you can track the link (reachability of the vpn peer) and map it to a route.

Check the below link for configuration details


This Discussion