Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Failover between Serial (MPLS) and Ethernet (VPN)

Greetings all,

So here is the challenge I am comming up against.  I have a 1941 router with the security  licence.  I am setting up both a T1 wic that connects to my enterprise MPLS cloud and one of the two gig interfaces that will connect to my home office through a VPN tunnel to a ASA 5520.  I have tried multiple solutions though my gues is that I am making this WAY more difficult than it needs to be.  What I am trying to create is a primary on the serial interface and then a failover through the VPN.

Any thoughts, suggestions are VERY welcome!

So far, I have tried to:

     Track the serial interface and then set the default route, based on the tracking

     Create an IP SLA to echo the gateway of the serial interface to change the routing

     Started to create HSRP between the two interfaces though I could not figure out if / how a standby could be put into a sub-interface on the serial

The SLA seems to be working somewhat.  The problem is that it is not transparent and sometimes even needs me to clear the VPN tunnel to get things back to smoothly through the serial interface.

Like I said, I am guessing that I am going about this in a WAY to complicated way. 

track 20 interface GigabitEthernet0/1 line-protocol


track 123 ip sla 1 reachability

crypto map LEVY-CRYMAP 10 ipsec-isakmp

set peer default

set transform-set ESP-AES-256-SHA

set pfs group1

match address CRYPTO-ACL


interface GigabitEthernet0/1

description $ES_LAN$

ip address

ip flow ingress

duplex auto

speed auto

crypto map LEVY-CRYMAP

ip route 15 track 20

ip route 153 track 123

ip access-list extended CRYPTO-ACL

permit ip any

permit ip any

permit ip host any

deny   ip any any

ip sla 1


ip sla schedule 1 life forever start-time now

event manager applet clearcrypto

event track 123 state any

action ds cli command "clear crypto sessions"


Thanks in advance,


New Member

Failover between Serial (MPLS) and Ethernet (VPN)


May be you should remove track configuration and try to do it with IP SLA only and it should work. I am using Cisco 2921 with similar scenario and its working fine, the only difference I see is - i had configured my HO MPLS routers as IP SLA responder. May be you should try that as well.


Pawan Sharma

CreatePlease to create content