Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Redundant VPN

We have a few site to site VPN connections with 5505's. Is there any way to setup a redundant config incase the first one goes down it would reestablish to a second firewall with a different ISP? I am using 5520's at both ISP's.

3 REPLIES
New Member

Re: Redundant VPN

You can create two peers for the VPN tunnels. But this will not solve your problem completely as the internal routing needs to be changed to the second pix when the first one fails. For options on changing the internal routing, we will need to know your setup better

New Member

Re: Redundant VPN

Thanks for the reply. Couldn't I just do a weighted route?

New Member

Re: Redundant VPN

You should be taking care of the routing part seperately. A weighted route will not work with PIX/ASA as the ethernet link will never go down unless the other end device goes down. However, you can track the link (reachability of the vpn peer) and map it to a route.

Check the below link for configuration details

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml

207
Views
0
Helpful
3
Replies