Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Dual IPsec tunnels for high availability

I have a highly available IPsec headend (2 routers running HSRP, RRI and IKE keepalive). The headend is in a DMZ and has IP hops to our network boundary.

I want to establish two IPsec tunnels from this headend to a client, one to their production site, and one to their backup site via a pair of Frame Relay links that terminate on two Client IPsec peer routers.

Under normal operation, I want traffic separation (eg. transaction traffic between transaction hosts on one IPsec tunnel, and ftp traffic between ftp hosts on the other IPsec tunnel.

Under failure conditions (one of the IPsec tunnels fails to establish for whatever reason), I want all traffic to use the remaining IPsec tunnel.

I can easily setup to have traffic separation if both tunnels are working, but am not sure how I'd configure to have the traffic use the alternate IPsec tunnel on failure of the preferred tunnel.

Any thoughts or suggestions most welcome.

The following diagram illustrates the setup.

Host1a uses Tunnel1 to talk to Host 1b

Host2a uses Tunnel2 to talk to Host 2b

On either tunnel failure, both sessions use remaining tunnel.


H1a-| <--- IPsec Tunnels --->

| ------ -------- -----------

|-|Head|----|WAN R1|- F/R PVC1 -|Client R1|-|

| ------ \ -------- ----------- |-H1b

H2a-| \ |

| \-------- ----------- |-H2b

|WAN R2|- F/R PVC2 -|Client R2|-|

-------- -----------

Sorry, the diagram lost its spaces when I posted.


Re: Dual IPsec tunnels for high availability

GRE over IPSec should help you. To see a configuration example, please see (you can ignore the parts dealing with IPX)