1
17.1 Legacy Series / Re: IPsec Site to Site Failover
« on: May 03, 2017, 11:07:10 pm »
This assumes that you already have the WAN failover aspect working.
To get IPSEC to failover, you have to define your phase 1s on both sides of the IPSEC link with Distinguished Name. You can't use the peer address because that address will change and the resulting IPSEC connection attempt will be denied. Distinguished Name is static. Also, you would need to have a dynamic DNS for your IP address that will update when the connection switches, and you use the dynamic DNS for your connection IP. That's about all there is to it if I remember correctly off the top of my head.
To get IPSEC to failover, you have to define your phase 1s on both sides of the IPSEC link with Distinguished Name. You can't use the peer address because that address will change and the resulting IPSEC connection attempt will be denied. Distinguished Name is static. Also, you would need to have a dynamic DNS for your IP address that will update when the connection switches, and you use the dynamic DNS for your connection IP. That's about all there is to it if I remember correctly off the top of my head.