cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
462
Views
0
Helpful
1
Replies

Failover on IPsec tunnels on ASA5520

bill.hurley
Level 1
Level 1

Good Day

I am trying to setup 2 IPsec tunnels to another company. We want to use one for the primary and the second for failover. I am wondering if this can be done using IPsec tunnels and if so how do I accomplish this.I have an ASA 5520 that I am using

Thanks

BH

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

Bill

If you are not talking about stateful IPSEC failover then the simplest way is to just specify the 2 vpn peers in your crypto-map ie.

crypto map set peer x.x.x.x y.y.y.y

where x.x.x.x is the primary peer and y.y.y.y is the secondary. The ASA will try the peers in order so if the first is not available then the second will be used.

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: