Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
victor_cortez
Contributor

IPSEC VSX load balance

Hello guys,

 

Here is my scneario, r81 Vsystem:

I have a vpn community IPSEC from my peer Ckp-Vs-SG to 2 different fgt peers, Fgt-A and Fgt-B.

MEP Manually:

Fgt-A is the primay under MEP

Fgt-B is the secondary under MEP

 

So now I want to send traffic to both Fgt-A and B and balance. How to set this on CKP side?

Route based it is not supported on vsx, right?

The final result is active/active VPN balancing traffic between the Fortigate side.

Tks,

Victor C

0 Kudos
4 Replies
Wolfgang
Authority
Authority

More detailed description would be helpful.

I understand Fgt as Fortigate at the remote site. This requires the use of DPD (DeadPeerDetection) with third party VPN gateways. Follow VPN redundancy does not work when establishing an IPsec VPN Tunnel with a third-party peer to configure.

0 Kudos
victor_cortez
Contributor

I want active/active balancing traffic through both Fortigates A and B.

0 Kudos
Wolfgang
Authority
Authority

I believe load balancing is not possible with third party.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Route based (VTI) is supported on VSX with dynamic routing (BGP) in R81.x

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events