Redundancy for Global protect VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Redundancy for Global protect VPN

L2 Linker
Dear Friends,
We have a customer who is Currently configured with GP- Global Protect for VPN is connecting with ISP-1, one Public IP / One ISP-Internet Service Provider.
 
Requirement is, can we configure as backup or as redundant with another ISP-2 ?
 
Purpose : Once One ISP is down, then GP- Global Protect users will not disconnect from remote VPN service. It will redirect with ISP-2 as like failover. 
 
Please confirm once, Is it possible? 
3 REPLIES 3

L4 Transporter

Hello,

 

Would this be for the GlobalProtect portal or the gateway? You could have you Globalprotect attached to a loopback interface and follow the steps from this post: LIVEcommunity - Nominated Discussion: Dual ISP Global Protect Redundancy - LIVEcommunity - 520124 (p...

 

If you're just worried about the Gateway and not the Portal you could have multiple Gateways created as well so in the event one goes down the clients will reconnect to the second gateway. If the portal is down in this scenario new users wouldn't be able to connect until thats back up but the active users shouldnt notice a difference.

 

I've seen posts previously saying people have done two separate portals and did a DNS round robin, however I personally haven't tested this. 

Thanks for responding, this is for global protect gateway..

Cyber Elite
Cyber Elite

Hi @Claw4609 and @ChandrashekharD ,

 

I have tested option 1 in this doc, and it works!  https://www.wandynamics.com/blog/ensuring-high-availability-globalprotect-vpn-portals

 

If you configure 2 gateways and save user name, the client caches the gateways.  If the portal is down, the client automatically connects to the 2nd gateway.  Configure portal and gateway on ISP-1.  Configure 2nd gateway on ISP-2.  List both gateways under the portal.  You could give gateway 1 the highest priority.

 

The doc also has options 2 and 3, which are (2) manually change portal and (3) GSLB.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 523 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!