Branch Office With Static Ip Addresses - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

VPN menu features
IPSec failover
After editing and saving ifmond.conf on the Branch office UTM Firewall, run the following command to load
7
the edits:
ipsec setup restart
Manually edit the ifmond.conf file on the Headquarters UTM Firewall to configure for IPSec failover and
8
fall forward.
Note:
At least one space must precede any text for the indented subsections within the ifmond.conf file.
##-- Custom entries MUST be added below this point
connection primary
parentipsec-tunnel-primary_1
parentofipsec-tunnel-primary_0
retry_delay5
test_delay5
maximum_retriesinfinite
startwhack --initiate --name primary_1 --asynchronous
testifretry 2 5 ping -I 192.168.11.1 192.168.12.1 -c 3
stopwhack --terminate --name primary_1 --asynchronous
connection secondary
parentipsec-tunnel-secondary_1
parentofipsec-tunnel-secondary_0
retry_delay5
test_delay5
maximum_retriesinfinite
startwhack --initiate --name secondary_1 --asynchronous
testifretry 2 5 ping -I 192.168.11.2 192.168.12.2 -c 3
stopwhack --terminate --name secondary_1 --asynchronous
service ipsec-failover
groupprimary
groupsecondary
After editing and saving ifmond.conf on the Headquarters UTM Firewall, run the following command to
9
load the edits:
ipsec setup restart
Enable both primary and secondary tunnels on the Headquarters and Branch Office UTM Firewalls. The
10
failover and fall forward are fully operational.

Branch Office with static IP addresses

The following scenario assumes that the Headquarters UTM Firewall and Branch Office UTM Firewall each
have two static Internet IP addresses
tunnel from its primary Internet IP address to the primary Internet IP address at the Headquarters UTM
Firewall as the primary IPSec tunnel path. If this IPSec connection is detected to have failed, a failover
IPSec tunnel is established from the secondary Internet IP address to the secondary Internet IP address at
the Headquarters UTM Firewall. Once in the failover state, the Branch Office UTM Firewall periodically
determines if the primary IPSec tunnel path is functioning again and, if so, falls forward to use the primary
link instead.
302
McAfee UTM Firewall 4.0.4 Administration Guide
(Figure
314). The Branch Office UTM Firewall establishes an IPSec

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents