Redundant VPN

Unanswered Question
naveen_b81 Thu, 02/26/2009 - 23:09

You can create two peers for the VPN tunnels. But this will not solve your problem completely as the internal routing needs to be changed to the second pix when the first one fails. For options on changing the internal routing, we will need to know your setup better

naveen_b81 Wed, 03/04/2009 - 01:39

You should be taking care of the routing part seperately. A weighted route will not work with PIX/ASA as the ethernet link will never go down unless the other end device goes down. However, you can track the link (reachability of the vpn peer) and map it to a route.

Check the below link for configuration details

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

Actions

This Discussion