cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
249
Views
0
Helpful
2
Replies

ezyvpn client to pix redundancy

jdickler
Level 1
Level 1

what mechanism would you use in a pair of pix's being used as headend vpn ezyvpn servers in order to have redundancy for ezyvpn clients.... How would the pix's dynamically advertise the routes for the clients they have acquired? The pix's in question are geographically separated over a wan so are not running in failover mode.

2 Replies 2

awaheed
Cisco Employee
Cisco Employee

Hi Dickler,

Yes you might have a solution if you have PIX firewalls as EzVPN clients, in the vpnclient command set you can define "vpnclient server ip_primary [ip_secondary_1 ip_secondary_2" which means The vpnclient server ip_primary ip_secondary_1[ip_secondary_2 ... ip_secondary_10] command enables you to create a backup VPN server list on the VPN client.

Additional details can be found at:

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801727ae.html#1048520

Regards,

Aamir Waheed,

Cisco Systems, Inc.

CCIE#8933

-=-=-

thanks for the response. However, the question is not how to configure it on the client but how to tell the current server to advertise the route to the client network.

Review Cisco Networking products for a $25 gift card