- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Site to Host IPSEC VPN ISP redundancy with Gateway...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site to Host IPSEC VPN ISP redundancy with Gateway behind static NAT
Hi,
I am trying to add a new ISP to my current setup so as to achieve redundancy for my remote user in case 1 of the ISP when down. The setup is as such. Firmware used is R80.10
ISP1 ISP2(New)
| |
Switch------------- Switch
| / \ |
Load balancer -------Load balancer (Static Nat)
| |
Switch------------Switch
| |
CP1-----------------CP2 (Active-Passive ClusteXL)
However it appears that only 1 ISP can be active at a time. Static NAT field in link selection only allow 1 IP to be inserted.
When i change it to ISP2 ip the ISP2 tunnel is active and the ISP1 is down. Btw this is for remote access (IPSEC site to host).
When i try to select probing under link selection and insert the IP for 2 ISP, it does not work either.
Is there anyway i could make this work?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes, you can have ISP redundancy. You have to enable this if you have defined two external interfaces on the gateway.
But I think behind two different NAT devices ( as mentioned by @Travis_G ) this is not possible.
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not exactly sure how it'd work in this case where some other device is doing the NAT.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have the same question. Can we have a ISP redundancy solution on the checkpoint ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes, you can have ISP redundancy. You have to enable this if you have defined two external interfaces on the gateway.
But I think behind two different NAT devices ( as mentioned by @Travis_G ) this is not possible.
Wolfgang
