Ipsec Failover; Branch Office With A Dynamic Ip Address - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

VPN menu features

IPSec failover

IPSec failover
The UTM Firewall appliance can be configured to failover and fall forward between IPSec connections. Two
common scenarios are described below.
Note:
IPSec failover is applicable to the following models only: SG560, SG560U, SG565, SG580, and SG720.

Branch Office with a dynamic IP address

The following scenario assumes that the Headquarters UTM Firewall has two static Internet IP addresses
and the Branch Office UTM Firewall has a dynamic Internet IP address
Firewall establishes an IPSec tunnel to the primary Internet IP address at the Headquarters UTM Firewall as
the primary IPSec tunnel path. If this IPSec connection is detected to have failed, a failover IPSec tunnel is
established to the secondary Internet IP address at the Headquarters UTM Firewall. Once in the failover
state, the Branch Office UTM Firewall periodically determines if the primary IPSec tunnel path is functioning
again, and if so, falls forward to use the primary link instead.
Figure 313 Example IPSec failover network
The steps necessary to recreate this failover scenario are:
Set up unused aliases on the LAN interfaces at both Headquarters and the Branch office. These aliases
1
will be used to determine if IPSec is functioning on either the Primary or Secondary paths.
Table 20 Aliases – Headquarters UTM Firewall configuration
Alias IP:
192.168.11.1
192.168.11.2
Table 21 Aliases – Branch Office UTM Firewall configuration
Alias IP:
192.168.12.1
192.168.12.2
Set up the "primary" IPSec tunnel with two subnets on both the Headquarters and the Branch Office UTM
2
Firewalls and make sure that it is working. For each field, use the default values unless an alternative
setting is given in
Table 22 Primary IPSec tunnel – Headquarters UTM Firewall configuration
Field
Tunnel name
Local interface
Local interface gateway
Keying
Local address
Remote address:
Local Optional Endpoint ID
McAfee UTM Firewall 4.0.4 Administration Guide
Alias subnetmask:
32
32
Alias subnetmask:
32
32
Table 22
or
Table
23.
Value
primary
<select interface for primary link>
Use Interfaces Default Gateway
Aggressive mode (IKE)
static IP address
dynamic IP address
primary@HQ
(Figure
313). The Branch Office UTM
299

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents