VPN Failover Configuration on Sophos UTM9

Subject: VPN Failover Configuration on Sophos UTM9

Good morning,

In my Sophos UTM9 cluster, I have two internet connections configured as ACTIVE/STANDBY. I have a LAN-to-LAN VPN currently running on the primary line. I'm trying to automate the process so that if WAN1 goes down, the VPN automatically switches to WAN2 (the secondary line).

I noticed that under UPLINK MONITORING → Actions, there are rules that can be created, including "Add Action If Uplink Goes Offline."

What is the correct way to configure this rule?

Would you recommend adding the backup VPN under the IPsec Tunnel field and setting the action to Enable? Any suggestions?
If I had two VPNs, I assume I would need to create the same rule twice, correct?

Looking forward to your feedback!
Thanks!

  • Hello,

    this is one way to do what you want to achieve. If the other site has one uplink, you need two tunnel definitions on your main site.

    If the other side has two WANs as well, you end up with four definitions.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.