Bob,
I'm attempting basically the same thing, however, I'm experiencing issues with the ISP failover VPNs over the PTP interface. They say Error: No connection and I notice the VPN ID's are different on each connection
Also, with uplink monitoring, how do you differentiate between the ISP connection and the PTP connection going down. How do you specify that the UTM needs to enable the Site to Site VPN over the internet connection, or the one over the PTP to redirect internet traffic?
I'm running UTM 9.403-4
Thanks,
JR
It's almost two years later and we have some new capabilities, JR. We'll use the OP's (Chris) scenario and I'll try to make this more precise.
Let's start with a redundant connection between the sites.
#1. In the Primary site:
#2. In the Secondary site:
Now, let's take care of the situation where a site loses its ISP connection and needs to get to the Internet via the PTP and the other site's connectivity. We'll do this for the Primary site.
#3. In the Primary site:
#4. In the Secondary site:
An additional configuration #5 and #6 comparable to #3 and #4 is needed to provide ISP redundancy for the Secondary site. Thus there are three tunnels needed to make this work. The trick is using "Respond Only" mode in the last two tunnels in the fail-over-to site and Uplink Monitoring Actions on the other site to switch between tunnels.
If at any point, the PTP goes down, the sites will instantly (a minute) hook up with each other over the ISP connections. If at any point, a site experiences a disconnect from its local ISP, it will shut down the tunnel between the two sites and establish a new one that gives local users access to both the other site and the Internet.
This should work as designed, but I've not actually done this this way before, so I would appreciate feedback as to its efficacy. TiA!
Cheers - Bob
PS The other way uses IPsec Connections bound to individual interfaces, routing and Multipath. I've seen this described in German and have copied that to the Wiki here.
Thanks Bob! I just got a chance to apply the configuration changes. I had some difficulty getting the first VPN up. I don't exactly remember how I resolved it, might have been some config from the first method still enabled. After I got it working I decided to attempt to test it by disabling the PTP interface. That didn't go over too well and after several minutes they didn't come back up. Re-enabling the interface didn't help either. I was receiving an error similar to a NAT issue. I eventually restarted both UTMs and the link came back.
I think simulating a failure that way is not the best test, or maybe I just wasn't patient enough.
I plan on testing the fail overs after hours sometime by actually disconnecting the PTP and unplugging the cable modem and seeing how everything reacts. I'll then report back on how the configuration works in real life.
Thanks again!
JR
Thanks Bob! I just got a chance to apply the configuration changes. I had some difficulty getting the first VPN up. I don't exactly remember how I resolved it, might have been some config from the first method still enabled. After I got it working I decided to attempt to test it by disabling the PTP interface. That didn't go over too well and after several minutes they didn't come back up. Re-enabling the interface didn't help either. I was receiving an error similar to a NAT issue. I eventually restarted both UTMs and the link came back.
I think simulating a failure that way is not the best test, or maybe I just wasn't patient enough.
I plan on testing the fail overs after hours sometime by actually disconnecting the PTP and unplugging the cable modem and seeing how everything reacts. I'll then report back on how the configuration works in real life.
Thanks again!
JR