?
Solved

Enterprise Routers and VPN

Posted on 2014-02-05
6
Medium Priority
?
245 Views
Last Modified: 2014-02-05
Hey guys

I need some shopping help here.  A customer wants to setup his three remote sites to have not only failover to an alternate ISP (which is easy) but also to have Auto Failover of his THREE VPN's.  I have seen a lot of routers but none really work very good on the VPN Auto Failover.  

Any ideas out there?
0
Comment
Question by:jonmenefee
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 22

Expert Comment

by:Matt V
ID: 39836317
What kind of VPNs are you talking about?  To other remote offices, "dial-in" remote worker VPNs or to third party partners and vendors?

If you are talking about the first two, then the configuration of the router determines more than which router you choose.

The third is an issue because the third party has to do some configuration on their end to support the connection from both ISPs.
0
 

Author Comment

by:jonmenefee
ID: 39836415
Three offices, Gateway to Gateway VPN is the preferred way.  IPsec VPN

Example.

Office A has the main server in it.  It has ATT and Comcast.  Their uptime is good.

Office B has Comcast and ATT also, but they are constantly having issues and Comcast goes offline more than online

Office C has Comcast and ATT also, but they don't have any problems.

B and C connect to A via Gateway VPN.  I need to make sure that if B goes down that its VPN will failover and reconnect to A with no end user intervention.

Thanks!!
0
 
LVL 22

Accepted Solution

by:
Matt V earned 2000 total points
ID: 39836462
If you are using Cisco routers, you can setup a DMVPN and use OSPF or EIGRP routing and the tunnels will failover nicely.

Basically each spoke site connects to a tunnel over each ISP, and then traffic will route over both, but continue to route if one goes down.

This is a really easy way to accomplish what you need.  There are other ways as well.

If you want to make sure the traffic goes over Comcast before ATT then you can weight the routes so that one gets traffic before the other.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:jonmenefee
ID: 39836497
Thanks, that does help a whole lot.
0
 
LVL 22

Expert Comment

by:Matt V
ID: 39836574
We did something similar but had two main offices with a fibre across the parking lot, so we set each spoke to connect to each head office, in case one lost Internet.

We used a Cisco 1921 for the hub (main office) and Cisco 881 routers at the remote locations.
0
 

Author Comment

by:jonmenefee
ID: 39837442
Thanks Matt!!
0

Featured Post

Plug and play, no additional software required!

The ATEN UE3310 USB3.1 Gen1 Extender Cable allows users to extend the distance between the computer and USB devices up to 10 m (33 ft). The UE3310 is a high-quality, cost-effective solution for professional environments such as hospitals, factories and business facilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question