cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3454
Views
0
Helpful
0
Comments
TCC_2
Level 10
Level 10

Resolution

You can define multiple addresses for a peer to connect as back-up when the IPSec tunnel to the primary headend device fails. this is an example:

crypto map VPN 10 ipsec-isakmp

set peer 192.167.1.6

!--- The primary headend. 

set peer 192.168.1.9

!--- The secondary peer.

match address 111

set transform-set ESP-3DES

Make sure to adjust the routing so the traffic is sent accordingly.

The secondary device is contacted if the IPSec tunnel to the primary device fails to connect.

Note: This is also applicable to PIX Firewalls.

For more information, refer to the Creating Static Crypto Maps section of Configuring Security for VPNs with IPsec.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: