Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
D_TK
Advisor

ISP redundancy and VPNs to azure

Hi everyone,

I have a cluster where we just added a 2nd ISP link and I've configured the normal ISP redundancy and VPN link selection configs like i have on my other dual circuit locations.  The one outlier at this location is that it also has a s2s with azure (vendor) and i would like to have this 2nd circuit be a backup for that tunnel as well.

Clearly it won't be as easy and seamless as the checkpoint to checkpoint tunnels are, but what do i need to do to enable this?  As an aside, i don't control the azure side, and will have to involve the vendor.

R81.20 cluster, r82 management.

Thanks much,

Danny

 

 

 

 

0 Kudos
1 Reply
the_rock
Legend
Legend

Hey Danny,

See, tricky part with ISP redundancy is that if there is isp link failure, other side would NOT know about the new IP, so tunnel definitely would not have been established. Now, one way to "manipulate" this is to create additional static route, but that would only really help for regular traffic, not VPN.

My colleague and I did bunch of stuff for redundant tunnels with harmony sase, let me see if I can find all the notes I took about it.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events