Configure Ipsec Failover - Digi Connect IT 16 User Manual

Hide thumbs Also See for Connect IT 16:
Table of Contents

Advertisement

Virtual Private Networks (VPN)

Configure IPsec failover

There are two methods to configure the Connect IT 16/48 device to fail over from a primary IPsec
tunnel to a backup tunnel:
SureLink active recovery—You can use SureLink along with the IPsec tunnel's metric to
n
configure two or more tunnels so that when the primary tunnel is determined to be inactive by
SureLink, a secondary tunnel can begin serving traffic that the primary tunnel was serving.
Preferred tunnel—When multiple IPsec tunnels are configured, one tunnel can be configured
n
as a backup to another tunnel by defining a preferred tunnel for the backup device.
Required configuration items
Two or more configured IPsec tunnels: The primary tunnel, and one or more backup tunnels.
n
Either:
n
SureLink configured on the primary tunnel with Restart Interface enabled, and the metric
l
for all tunnels set appropriately to determine which IPsec tunnel has priority. With this
failover configuration, both tunnels are active simultaneously, and there is minimal
downtime due to failover.
Identify the preferred tunnel during configuration of the backup tunnel. In this scenario, the
l
backup tunnel is not active until the preferred tunnel fails.
IPsec failover using SureLink
With this configuration, when two IPsec tunnels are configured with the same local and remote
endpoints but different metrics, traffic addressed to the remote endpoint will be routed through the
IPsec tunnel with the lower metric.
If SureLink > Restart Interface is enabled for the tunnel with the lower metric, and SureLink
determines that the tunnel is not functioning properly (for example, pings to a host at the other end of
the tunnel are failing), then:
1. SureLink will shut down the tunnel and renegotiate its IPsec connection.
2. While the tunnel with the lower metric is down, traffic addressed to the remote endpoint will
be routed through the tunnel with the higher metric.
For example:
Tunnel_1:
n
Metric: 10
l
Local endpoint > Interface: ETH2
l
Remote endpoint > Hostname: 192.168.10.1
l
SureLink configuration:
l
Restart Interface enabled
o
Test target:
o
Test type: Ping test
o
Ping host: 192.168.10.2
o
Tunnel_2:
n
Digi Connect IT® 16/48 User Guide
IPsec
257

Advertisement

Table of Contents
loading

This manual is also suitable for:

Connect it 48

Table of Contents