Cisco Support Community
Community Member

VPN Failover question

Thank you so much for taking the time to help.

I have been tasked to configure a VPN failover design so that if the customer's Metro Ethernet connection fails, (EIGRP not in route table) a VPN connection will initiate autmatically. The Remote site will be the only one to initiate the connection to resources on the main site.

I have included a basic drawing, the main site is on the left, the firewall is an ASA5510, on the right is the remote site that will initiate the vpn request if needed. Their equipment is a 2811 with the 12.4 security.

My issue seems to be that in my config when I apply the crypto to the dsl line the network shows up as a connected route. This allows me to access resources but locks the vpn up and the Metro E is ignored no matter what its status. The remote site acts as if the only path to connect is via the VPN.

I thought there has to be some sort of Policy Based Routing I need to perform but not sure as to how to go about it.

Attached is a basic drawing of the network.


Re: VPN Failover question


If I understand your requirement correct, the Branch office network need to reach the head office via VPN when the HQ network not being learned via EIGRP (or metroethernet issues). If you have default routes ( on both ends points to Internet, and Lan to lan VPN between both ends configured correct, then it will work with no issues. if you want to define more specfic paths, add static routes on both ends with more higher administrative distance than EIGRP pointing to Interent path.



Community Member

Re: VPN Failover question

Thanks for the quick response. That's what I thought too but what is happening is once I put the crypto statement on my internet interface it sees the vpn destination network as a connected route. So when I reconnect the Metro E, that route is ignored. it never makes it to the routing table because a connected route beats out any other metric. I will check it again to confirm.

Community Member

Re: VPN Failover question

Disregard my last, the config does work. I found out that one of my route maps to change metrics was fat fingered.

It's working G R E A T now. :-)

CreatePlease to create content