Help me create an IPSEC failover for a headquarters and branch office with 2 gateways each. I would like to create a high availability scenario, as the links in both locations fluctuate a lot.
I thought about doing it like this:
The Branch initiates and the Headquarters responds.
ISP1 (Branch) <> ISP1 (headquarters)
ISP2 (Branch)
ISP1 (Branch) <> ISP2 (headquarters)
ISP2 (Branch)
In this scenario I am considering that Matrix would respond to any of the gateways that initiate.
But I also thought about this other scenario:
ISP1 (Branch) <> ISP1 (headquarters)
ISP2 (Branch) <> ISP1 (headquarters)
ISP1 (Branch) <> ISP2 (headquarters)
ISP2 (Branch) <> ISP2 (headquarters)
I'm in doubt whether 4:2 or 4:4 serial connections.
Hi Lais,
Thank you for reaching out to Sophos Community.
I would recommend reaching out to your Sales Partner/Sales Engr as this query would be best answered by them so that they can fully check your resources and requirements.
As you have stated, the current tunnel fluctuates a lot. What could happen if you added more VPNs? Therefore, kindly contact them to further assist you with your environment.
Erick Jan
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Hi Lais, Additionally I would suggest going with the RBVPN tunnel type with a combination of SD-WAN profile which gives more flexibility and parameters to manage failover compared to the legacy PBVPN tunnel type Failover group.
Regards,
Vishal Ranpariya
Technical Account Manager | Global Customer Experience
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question, use the 'Verify Answer' link.
Hi Lais Medeiros,
It is simple Just Go to Site-to-Site VPN > IPSec > Failover group > Select (Add) > Name Group > Select available connections ISP1 and ISP2 > Checkmark (automatic failback option > Save.
Thanks,
Vaibhav