cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
658
Views
4
Helpful
5
Replies

Reg: Dynamic Switching of VPN client for Dual ISP

Dear Experts,

I was enclosed my network scenario.

I have two ISP connections. One is primary and other one is secondary.

Regardsing Primary ISP, i have two types of IPs. One is WAN IP pool and other one is public pool to used for DMZ.

WAN ip i configured in Router outside interface and LAN public pool  i configured between Router inside interface and Firewall outside interface( Firewall is accessble from internet with the public IP configured on outside interface)

In firewall i terminated Secondary ISP directly on interface called backup.

Firewall configured for ISP failover with sla tracking and its working fine. And firewall also configured for IPSec remote access VPN for mobile users. This is also working fine.

But here i am facing problem with VPN users that whenever primary ISP link was down the VPN user has getiing disconnecting. The user has manullay shifted to the secondary ISP that was configured in VPN client software in user machine.

Is there any way of shifting dynamically one ISP to another ISP when one of ISP got problem.

Regards,

Janardhan

5 Replies 5

Vivek Ganapathi
Level 4
Level 4

Hello Janardhan,

Below is a link which has a discussion on the similar topic in the forum. This may help you.

https://supportforums.cisco.com/community/netpro/security/vpn/blog/2011/04/25/ipsec-vpn-redundancy-failover-over-redundant-isp-links

Thanks

Vivek

*please do rate if helpful

HI Mr. Vivek,

Thanks for your prompt reply. I am verifying same with my customer. I hope

it will work.

I have on more query on this. How can i use my primary ISP given public IPs

through the secondary ISP when my primary ISP was down.

Regards,

Janaradhan

On Wed, Jan 25, 2012 at 5:54 PM, v.ganapathi <

You cannot use the primary ISP routable IP pool on your secondary ISP.

HI Mr. Vivek,

If i run BGP in my router, then it will advertise my primary public pool to

the secondary ISP. Is right or not???

Regards,

Janardhan

On Wed, Jan 25, 2012 at 7:52 PM, v.ganapathi <

Yes, you may advertise it, but when you loose the reachability to your primary ISP, ultimately you loose your BGP session as well & then even your advertisements

Hope its clear.

Thanks

Vivek

Review Cisco Networking products for a $25 gift card