ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

ikev2 site to site VPN to sites with multiple public ip addresses(used for failover)

L1 Bithead

for a client, i created these many tunnel interfaces for each of their sites. Now, for all these sites, they have 2-3 public ip addresses(for failover purposes). So, will i have to create new tunnel interfaces or should I just create new Ike gateways and ipsec tunnels and point them to the tunnels which I created earlier(shown on the screenshot below)? Please help

 

msdphi_0-1707168908909.png

 

6 REPLIES 6

Cyber Elite
Cyber Elite

Hello,

I think your answer would depend on how you plan to use the tunnel interfaces. You can assign multiple IP's to a singe interface. However for me, I use the interfaces for OSPF routing and to see if the tunnel is up, via 3rd party monitoring since the tunnels connect via different providers.

Regards,

I want to know how to configure policy based site to site VPN from our Palo Alto to a site which has a watchguard firewall and has 3 public ip addresses(used for failover).

Cyber Elite
Cyber Elite

Hello,

Is a watchguard a route based or zone based firewall? Palo Alto is route based.

Regards,

I am not sure about that. That is on the client's side.

L1 Bithead

I am just configuring on panorama. I have already configured VPN to their primary public IP. I am not sure if I can point the same tunnel to the newly created ike gateways and ipsec tunnels for their branch sites. 

Cyber Elite
Cyber Elite

Hello,

You should be able to, however make sure your routing is set so that its not going to use multiple tunnels unless you are using ECMP.

Regards,

  • 430 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!