Virtual Private Networks (VPN)
IPsec
IX20 User Guide
288
Configure IPsec failover
You can configure the IX20 device to fail over from a primary IPsec tunnel to a backup tunnel.
During configuration of the backup IPsec tunnel, identify the primary IPsec tunnel in the
Preferred
tunnel
parameter. The
Preferred tunnel
parameter instructs the backup IPsec tunnel to start only
when the preferred tunnel has been determined to have failed. It will continue to operate until the
preferred tunnel returns to full operational status.
Required configuration items
n
Two configured IPsec tunnels: The primary tunnel, and the backup tunnel.
n
Identify the primary tunnel during configuration of the backup tunnel.
WebUI
1. Configure the primary IPsec tunnel. See
for instructions.
2. Create a backup IPsec tunnel. See
for instructions.
3. During configuration of the backup IPsec tunnel, identify the primary IPsec tunnel in the
Preferred tunnel
parameter.
4. Click
Apply
to save the configuration and apply the change.
Command line
1. Configure the primary IPsec tunnel. See
for instructions.
2. Create a backup IPsec tunnel. See
for instructions.
3. During configuration of the backup IPsec tunnel, identify the primary IPsec tunnel:
a. Use the
?
to view a list of available tunnels:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover ?
Preferred tunnel: This tunnel will not start until the preferred tunnel
has failed. It will continue
to operate until the preferred tunnel returns to full operation status.