Cisco Support Community
Community Member

VPN and Routing


I have a scenario where I would need to set up failover using a 1720 router connecting to two different ISP'S and a Pix 501 behind it.How would the failover work, specially the configs that need to go on the pix so it knows how to get to the destination when one line goes down?

At the main office I'll have a 515 ending all the remote VPN tunnels.

Has anybody configured something similar? I'm doing some research to find the solution but any suggestions would be really appreciated.

remotes: pix>rtr>isp1 and isp2

Main site: pix>rtr>isp1 and isp2

Thanks very much...

Cisco Employee

Re: VPN and Routing

If the two ISP circuits terminate on the router, and you then have an ethernet port from there to the PIX's outside interface, then you don't need to do anything special on the PIX at all. Just set the PIX's default route to be the routers ethernet interface, and everything should work fine, provided the router is set up correctly to be able to route out to both ISP's.

I'm sure you're not going to be receiving a full Internet routing table on the 1720's from both ISP's, so I'd probably suggest setting a default route on the 1720 to point to one specific ISP, and then setting a floating-static default route pointing out the other one. That way all traffic will go via one ISP, and if that goes down it'll go via the other.

Community Member

Re: VPN and Routing

Thanks for the insight; I think I was making more complicated than what it is.



Re: VPN and Routing

For redundancy to provide higher availability, three things must be present:

1 - The ability to detect a failure

2 - The ability to select an alternate path

3 - The availability of the alternate path when it is actually needed.

The challenge in typical low cost (cable modem & DSL) redundant ISP setups is #1. There is no way to detect the loss of an ISP, whether due to link, PIX, ISP or other failure. Low cost providers generally are not willing to do BGP with you, and the Ethernet interface on the cable/DSL modem stays up regardless of the state of the ISP link.

What you appear to be seeking is "ping directed routing" where ping or some other non-routing mechanism is used to detect when an ISP is no longer useable. All traffic can then be directed to flow to the remaining ISP. This is a feature which has been mentioned as being in the Cisco pipeline, but as of yet does not appear to be available. SOHO boxes from a few other vendors, do have the capability. Take at look at the Symantec 200R (previously known as the Nexland Pro800 turbo) to get an idea of what can be done.

Note that this technique really only works for inside users browsing the net. As a mechanism for inbound services, it is only appropriate for email (using multiple MX records, one per ISP path).

Good luck and have fun!

Vincent C Jones

Community Member

Re: VPN and Routing

Hi Vincent. What if i am using 2 1721 router to establish VPN? and one of the site having 2 connection(ADSL as primary and lease line as backup). Will the SAA work just like other "dual-WAN failover box" and allow VPN connection to have redundency as well?

CreatePlease to create content