Solved

VPN failover

Posted on 2004-09-21
5
385 Views
Last Modified: 2008-03-03
Here is my set up:
Home office has a T1 and a Cablemodem (When the T1 goes down we route traffic to the cablemodem router).  Each has a cisco 831 router 192.168.2.1 and 192.168.2.2 respectively on our lan.

Remote offices (with cisco 806 or 831's) VPN into the T1 router.

My questions is: With this set up is it possible to have the remote offices establish a vpn with the cablemodem router in the event that the T1 fails?
If not, what kind of setup/hardware would I need to get the desired result here.
0
Comment
Question by:frieked
  • 2
5 Comments
 
LVL 11

Expert Comment

by:PennGwyn
ID: 12114406
The fact that the traffic is VPN is a side issue.  This is really the same question as fail-over from one ISP to another, which seems to get asked here about once a week.  And there really isn't a cheap answer for incoming traffic.

Does your T1 fail often?  Is there another provider in your area?

0
 
LVL 3

Author Comment

by:frieked
ID: 12135927
Any faults in the T1 are a problem for us, we've already switched from another service provider because they were down too much.

Losses from non-VPN traffic are negligible to us but when our satelite offices lose the connection to our corporate office it causes major problems for us.

Ideally:
We want all of our branch offices (each with a cisco 831) to have 2 ipsec tunnels to the corporate office, one to each of the 2 routers there (831 also).
One of the tunnels would have higher priority and be used as default route to the corporate office and it would only use the 2nd tunnel if the first connection went down for whatever reason.

Please let me know if this could be done with our current setup or if it’s possible with another combination of hardware.  Don't consider money as an issue here in your answer.
Thanks
0
 
LVL 3

Author Comment

by:frieked
ID: 12147492
I found the answer to my question:
http://www.cisco.com/univercd/cc/td/doc/product/software/ios123/123newft/123t/123t_7/gtdpmo.htm
Configuring DPD and Cisco IOS Keepalives with Multiple Peers
in the Crypto Map
To configure DPD and IOS keepalives to be used in conjunction with the crypto map to allow for stateless failover, perform the following steps. This configuration will cause a router to cycle through the peer list when it detects that the first peer is dead.

SUMMARY STEPS
1. enable

2. configure terminal

3. crypto map map-name seq-num ipsec-isakmp

4. set peer {host-name [dynamic] | ip-address}

5. set transform-set transform-set-name

6. match address [access-list-id | name]

DETAILED STEPS
   Command or Action  Purpose  
Step 1
 enable

Example:
Router> enable
 Enables privileged EXEC mode.

•Enter your password if prompted.
 
Step 2
 configure terminal

Example:
Router# configure terminal
 Enters global configuration mode.
 
Step 3
 crypto map map-name seq-num ipsec-isakmp

Example:
Router (config)# crypto map green 1 ipsec-isakmp
 Enters crypto map configuration mode and creates or modifies a crypto map entry.

•The ipsec-isakmp keyword indicates that IKE will be used to establish the IPSec SAs for protecting the traffic specified by this crypto map entry.
 
Step 4
 set peer {host-name [dynamic] | ip-address}

Example:
Router (config-crypto-map)# set peer 12.12.12.12
 Specifies an IPSec peer in a crypto map entry.

•You can specify multiple peers by repeating this command.
 
Step 5
 set transform-set transform-set-name

Example:
Router (config-crypto-map)# set transform-set txfm
 Specifies which transform sets can be used with the crypto map entry.

•You can specify more than one transform set name by repeating this command.
 
Step 6
 match address [access-list-id | name]

Example:
Router (config-crypto-map)# match address 101
 Specifies an extended access list for a crypto map entry.
 
0
 

Accepted Solution

by:
modulo earned 0 total points
ID: 12663616
PAQed with points refunded (125)

modulo
Community Support Moderator
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question