Consider a local management- and log server (SMS) and a gateway (cluster) on location A.
What is best practice to setup a remote gateway (cluster) on location B, under control of the SMS on location A.
Locations A and B are connected over the Internet.
My first thought is to setup a site-to-site IPSec VPN between the two sites and have the management traffic passing the VPN.
However, if the VPN fails (e.g., due to an incorrect policy installation), we also loose the management connection to location B. And there is no (easy) way to install the proper policy to get the VPN working again.
Should we keep the traffic between the SMS and location B outside (independent of) the VPN connection?
If so, I remember you must make quite a few exceptions (including manual editing of *.def files on the management server) to keep the SMS traffic outside the VPN…
-Frank