Configuring VPN with redundant ISP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Configuring VPN with redundant ISP

L3 Networker

Hi guys,

I want to know it`s possible to configure a VPN with redundant ISP.

I configure the VPN to use a 1 ISP , when this 1 ISP fail , my vpn go to my 2 ISP.

It`s possible to do it ?

Best Regards.

Thiago Lima.

5 REPLIES 5

L6 Presenter

Hi...Are you asking about SSL VPN for mobile users or site-to-site VPN?

Site-to-Site

You can create 2 VPN tunnels, 1 tunnel on each ISP, and let dynamic routing handle the failover.  Thanks.

My other Firewall doesn't support two tunnels for the same network destination.  I  need establish vpn through link 1,  when this link fails the vpn needs renegotiate in link 2.

In the other Firewall (Sonicwall Pro 2040) there are just one Link for internet/VPN. The VPN configuration don't have the IP of peer,  it's set 0.0.0.0. No matter what IP Palo Alto uses for initiate VPN, becauses Sonicwall accept any of IP in source.

Thanks

You can try the method discussed here:   https://live.paloaltonetworks.com/docs/DOC-3376

Thanks.

  • 2824 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!