Load Balancing and Redundancy
6-2
Hewlett-Packard Company Virtual Private Networking Concepts Guide
Redundancy
Redundancy
Redundancy
Redundancy
Because the VPN device is such a critical device of a virtual
private network (VPN), you should have more than one VPN
device supporting the network. By placing more than one VPN
device in parallel, the network can continue functioning even if
one of the VPN device devices has to be shut down for any
reason. This is known as redundancy. Another reason for having
more than one VPN device in parallel is to handle more than 1024
active sessions, which is the maximum for a single VPN device.
Redundancy can be implemented for single-user tunnels and for
multiuser tunnels only. You cannot apply redundancy to site-to-
site tunnels. The reason for this is that redundancy relies on the
Client IP address, which only exists for remote user tunnels. You
need the Client IP for the device on the red network to know
which VPN device to send its replies to. In other words, a
different set of Client IPs is used on each gateway.
An example of redundancy is shown in the following figure.
Figure:
Figure:
Figure:
Figure: Enterprise Redundancy
Enterprise Redundancy
Enterprise Redundancy
Enterprise Redundancy