Shayne Sales
asked on
Juniper SSG5 Failover
I have a Juniper SSG5 Screen OS 6.2.0 running in Failover mode, everything works fine.
But I have been hit up with a scenario, that I do not know if it is possible.
Eth 0/0 ISP1
Eth 0/1 ISP2
Can I have a VPN on Eth 0/0 that if ISP1 goes down, will failover to Eth 0/1 ISP2? (Simply Yes, but please read on)
While with the above VPN failover, can I have all other traffic go out Eth 0/1 ISP2, and fail over to Eth 0/0 ISP1 if ISP2 goes down?
Hope that makes sense.
Thanks In Advance for any responses.
But I have been hit up with a scenario, that I do not know if it is possible.
Eth 0/0 ISP1
Eth 0/1 ISP2
Can I have a VPN on Eth 0/0 that if ISP1 goes down, will failover to Eth 0/1 ISP2? (Simply Yes, but please read on)
While with the above VPN failover, can I have all other traffic go out Eth 0/1 ISP2, and fail over to Eth 0/0 ISP1 if ISP2 goes down?
Hope that makes sense.
Thanks In Advance for any responses.
If you have it set up with the correct weighting, then your B Firewall will fail back over to your M Firewall once it's able to re-establish connectivity.
ASKER
So your saying that a SSG5 can do a "Active/Active" Dual ISPs?
What about the VPN situation, can I weight that in a sense, that it will re-eastablish the VPN on the secondary connection should the primary become un-available?
And I can weight it that all "HTTP/HTTPS" type traffic goes out the secondary, and weight it so the traffic destined for the VPN goes out the Primary?
Right now, the default failover is "Active/In-Active" since the Primary port is being used and the Secondary port is always set to Down status until failover.
What about the VPN situation, can I weight that in a sense, that it will re-eastablish the VPN on the secondary connection should the primary become un-available?
And I can weight it that all "HTTP/HTTPS" type traffic goes out the secondary, and weight it so the traffic destined for the VPN goes out the Primary?
Right now, the default failover is "Active/In-Active" since the Primary port is being used and the Secondary port is always set to Down status until failover.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.