This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

how to configure an IPsec VPN failover with 2 gateways on each end

Help me create an IPSEC failover for a headquarters and branch office with 2 gateways each. I would like to create a high availability scenario, as the links in both locations fluctuate a lot.

I thought about doing it like this:

The Branch initiates and the Headquarters responds.

ISP1 (Branch)      <>  ISP1 (headquarters)
ISP2 (Branch)


ISP1 (Branch)     <>   ISP2 (headquarters)
ISP2 (Branch)

In this scenario I am considering that Matrix would respond to any of the gateways that initiate.

But I also thought about this other scenario:

ISP1 (Branch) <> ISP1 (headquarters)
ISP2 (Branch) <> ISP1 (headquarters)
ISP1 (Branch) <> ISP2 (headquarters)
ISP2 (Branch) <> ISP2 (headquarters)

I'm in doubt whether 4:2 or 4:4 serial connections.



This thread was automatically locked due to age.
  • Hi Lais,

    Thank you for reaching out to Sophos Community.

    I would recommend reaching out to your Sales Partner/Sales Engr as this query would be best answered by them so that they can fully check your resources and requirements. 

    As you have stated, the current tunnel fluctuates a lot. What could happen if you added more VPNs? Therefore, kindly contact them to further assist you with your environment.

    Erick Jan

    Global Community Engineer, Support & Services
    Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
    If a post solves your question, please use the 'Verify Answer' button.

    The award-winning home for Sophos Support videos! - Visit Sophos Techvids

  • Hi Lais Medeiros,

    It is simple Just Go to Site-to-Site VPN > IPSec > Failover group > Select (Add) > Name Group > Select available connections ISP1 and ISP2 > Checkmark (automatic failback option > Save.

    Thanks,

    Vaibhav