Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rigarzag
New Contributor

Redundant VPNs in different units and diferent locations.

Hi,

I´m using Hub and Spoke VPNs, 1 hub and six spokes.  Behind the hub and every spoke there are multiple sites (locations), everyone with its own LAN segment, connected whit microwave links. It´s working all good.

But now I need to have redundant or backup vpns connections. Is it possible that this new VPN connections can be placed in a different location than the actual spoke or hub are??

This new location must have an ISP and a fortigate unit, and the redundant VPN needs to be enabled only when the primary VPNS gets down.  How can I do this ?

 

Thanks

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

It's completely depending on what the network needs at the new location. If the location just needs to reach the hub resources when the primary circuit goes down, you just need another ISP at the location and set a backup vpn to the hub, then set up one of options to do fail-over. V6.2's aggregate IPSec would be one of them.

 

However, if that location needs to reach other remote location's resources via the hub, and needs to have a backup path even when the hub location goes down, you obviously needs a secondary hub elected and route through the second hub over the second vpn. And the same would go to the destination side.

 

If your network requirements are expecting that level of redundancy, it's time that a routing protocol, or multiple, need to be considered and implemented. I have my personal preference (iBGP between two hubs, and eBGP between hubs to spokes) but there are many ways to design a network with routing protocol. It's getting into "network engineering" territory so if you're not comfortable with designing OSPF, BGP, etc. networks, you might need to get a network consultant involved.

emnoc
Esteemed Contributor III

Okay, so what you need to do is to draw out the design. I 've attached a multiple site von where hubs are attached to core service via HUBs. The design relies on OSPF and route-based tunnels. In this case, ALL tunnels are up and could be active, if you want to weigh one site primary, you adjust the ospf-metric for the tunnels.

 

In this case, you can do maintenance and one hub and the traffic will be carried to the 2nd hub. If a ISP or path goes down between HUB and one of them spoke, it will automatically use the 2nd HUB if the routes are up and vpn is active.

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors