Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

VPN Concentrator failover


i have two cisco 3060vpn concentrators. one is in prodution and the other is in spare. i am planning to install spare vpn concentrator in failover mode so that if the current vpn concentrator goes down then the new vpn concentrator will take the charge.i was planning to configure VRRP on both the vpn concentrator but then i came to know that VRRP only gives redandancy to vpn tunnels. currently there are lot of remote users are logging in my network through vpn profile so i want minimum downtime incase of primary vpn concentrator goes down.please give me appropriate solution for failover setup.


Re: VPN Concentrator failover

VRRP is configured on the public and private interfaces in this configuration. VRRP applies only to configurations where two or more VPN Concentrators operate in parallel. All participating VPN Concentrators have identical user, group, and LAN-to-LAN settings. If the Master fails, the Backup begins to service traffic formerly handled by the Master. This switchover occurs in 3 to 10 seconds. While IPsec and Point-to-Point Tunnel Protocol (PPTP) client connections are disconnected during this transition, users need only to reconnect without changing the destination address of their connection profile. In a LAN-to-LAN connection, switchover is seamless

CreatePlease to create content