Hello all, sorry if this is already answered before, I've searched here and couldn't find anything related.
We have a customer that we need to establish an "HA" IPSEC VPN, they have 2 remote peer addresses, let's name them site A and site B, both using Cisco ASA, being site A the peferable one, if it becomes unavailable, we would still have VPN established with site B.
I have a local R80.40 GW. I know I can set a VPN community and add both interoperable devices to it, but how can I be sure that the traffic would only go to site B if site A is unavailable?
I also know that I could create 2 vpn communities, but if I do that I think I would have problem with the encryption domain because they would be the same, right?
What would be the best way to achieve this setup?
Thanks!