Hot!IPSec-VPN Backup Line on MPLS connection

Author
posemman
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2021/01/14 20:05:16
  • Status: offline
2021/01/14 23:14:55 (permalink)
0

IPSec-VPN Backup Line on MPLS connection

Hi all
 
Do you have any idea on how to set-up IPSec-VPN connection(on fortigate) as a back-up line on existing MPLS?
Including also the automatic failover?
 
 
 
#1

7 Replies Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 2450
    • Scores: 237
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: IPSec-VPN Backup Line on MPLS connection 2021/01/15 09:35:55 (permalink)
    0
    That's depending on how traffic is routed through MPLS now. If everything is static, you need to have higher cost/distance static routes on the IPSec side for the same destinations. But if it's learning routes via routing protocol, generally need to use the same protocol over the IPSec but adjust some metrics not to prefer the backup side.
    If static, you likely need to set link-monitor to detect a disconnection to the destination over MPLS and remove the primary static route.
    #2
    posemman
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/14 20:05:16
    • Status: offline
    Re: IPSec-VPN Backup Line on MPLS connection 2021/01/17 18:33:45 (permalink)
    0
    Hi Toshi,
     
    Thank you for your answer.
    Our MPLS use EIGRP routing protocol, is it possible to fortigate to use EIGRP?
     
    #3
    posemman
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/14 20:05:16
    • Status: offline
    Re: IPSec-VPN Backup Line on MPLS connection 2021/01/17 19:32:31 (permalink)
    0
    Since we are using EIGRP on MPLS, and fortigate is not compatible on it.
    Is it advisable to create additional static route as a countermeasure for IPSec VPN backup line set-up?
     
    1. Keep Existing main routing(EIGRP)
    2. Create new route(static route) to each sites with higher administrative distance.
     
    May I know your input on this if its good design?
    #4
    Yurisk
    Gold Member
    • Total Posts : 182
    • Scores: 32
    • Reward points: 0
    • Joined: 2011/12/04 03:30:01
    • Status: offline
    Re: IPSec-VPN Backup Line on MPLS connection 2021/01/18 01:32:41 (permalink)
    0
    As EIGRP is not supported by Fortigate, it means you have your MPLS terminating on equipment that does support EIGRP (Cisco), so EIGRP and its routing is of no interest/concern to the Fortigate.
     
    I see 2 possible scenarios here:
    - You have say 2 connections on Fortigate - one to Cisco that itself connects to MPLS and runs EIGRP (or may run anything, as said - no business of FGT), and another to the ISP/Internet over which you bring up IPSec VPN. What is left is:
    • Have in Fortigate 2 static routes to the remote network, one via Cisco/MPLS and another via IPSec VPN tunnel interface auto-created when you configured the VPN. You want to set different priority for routes accordingly to the way you want to reach the remote network.
    • Decide how you want Fortigate to detect failure of one of those 2 connections. Link-monitor would do the trick by using, e.g. ping to detect when a link fails.
    - Second scenario is to let go of the static routing in Fortigate, set up dynamic routing between Cisco of MPLS and Fortigate, say OSPF, redistribute EIGRP routes to OSPF process on Cisco which will advertise them to Fortigate, run dynamic routing protocol in Fortigate over the IPsec VPN with the remote VPN peer (actually optional, but then you have to configure link-monitor and lose benefit of dynamic routing in detecting the link failure), set dynamic protocols routes policy on Fortigate to prefer MPLS or IPSec path to reach the remote network, congratulate yourself on making it through and knowing that only you can support all this :) (just kidding, it is not that complex)
     
    HTH
     
    #5
    Toshi Esumi
    Expert Member
    • Total Posts : 2450
    • Scores: 237
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: IPSec-VPN Backup Line on MPLS connection 2021/01/18 08:29:48 (permalink)
    0
    By the way, it's obvious but don't forget you do whatever you choose in Yuri described on both ends. Both sides need to move to the backup path at the same time and fail-back too.
    #6
    posemman
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/14 20:05:16
    • Status: offline
    Re: IPSec-VPN Backup Line on MPLS connection 2021/01/20 19:37:24 (permalink)
    0
    Thank you Yurisk for the suggestion.
    We are now planning to use the 2nd scenario which is to use dynamic routing on each site for IPSec line.
     
    I have question cause I'm not familiar in redistribution of routes thru Fortigate.
    can you give me example on how to set-up the redistribute EIGRP routes to OSPF process on cisco which will advertise them to fortigate.
     
    Hoping for your help. Thank you.
    #7
    posemman
    New Member
    • Total Posts : 9
    • Scores: 0
    • Reward points: 0
    • Joined: 2021/01/14 20:05:16
    • Status: offline
    Re: IPSec-VPN Backup Line on MPLS connection 2021/01/25 19:10:49 (permalink)
    0
    Hi all,
     
    Since we are using EIGRP on MPLS router, do I need to create OSPF on that router to be able to connect it on fortigate?
    #8
    Jump to:
    © 2021 APG vNext Commercial Version 5.5