cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
221
Views
0
Helpful
1
Replies

Second outside connection for vpn traffic

jbuncombe
Level 1
Level 1

I have installed a secondary outside connection to handle client and eventually site to site vpn traffic. Client connections through the primary outside connection still work, however when a client attempts to connect through the secondary connection they receive a "Peer no longer responding" error. I can see that the PIX receives the initial IKE connection, but the status stays at AG_INIT_EXCH and eventually times out.

How do I enable the secondary connection for this scenario?

1 Reply 1

tmoreo
Level 1
Level 1

When you say secondary outside connection. Did you get another range of IP's.

If so, It will be a great challenge. As far as I understand the PIX can only have one default gateway. I'm assuming your current default gateway points to the existing internet connection. So any traffic going to the PIX through the new connection will want to return through the first connection. Assuming you can get it to work, this will defeat your efforts.

I am also assuming that you have tested and gotten the VPN to work before ordering a new line. If not get the VPN to work first then figure out how to off load the traffic.

You might also be able to use two interfaces as outside interfaces. I have never done this and it probably is more of a headache to implement and support and not recommended.

Two solutions off the top are to implement BGP with the two providers if you are in a contract you cannot get out of.

Or just up the bandwidth from your current provider.