Solved

VPN failover on switch or on FW

Posted on 2014-12-15
6
121 Views
Last Modified: 2014-12-18
I need feedback on the preference to implement VPN failover on a layer 3 switch or on a FW. Basically, I will have a layer 3 switch connecting to a primary MPLS connection and the Internet as the VPN backup. My question is which scenario is best practice: 1 or 2 (see below)

scenario 1:
internet<-->fw<-->3560x<-->internal
                                |
                              MPLS CE router

scenario 2:
internet<-->fw<-->3560x<-->internal
                     |
            MPLS CE router
0
Comment
Question by:leblanc
  • 4
  • 2
6 Comments
 
LVL 20

Expert Comment

by:netcmh
ID: 40501423
What is your FW? Where is the VPN configured? I would go with the FW handling your VPN failover.
0
 
LVL 1

Author Comment

by:leblanc
ID: 40501843
I am still shopping for FWs. But it will be between a Fortinet and a Juniper. So if i understanding correctly, scenario 2 is the prefer way? Thanks
0
 
LVL 20

Accepted Solution

by:
netcmh earned 500 total points
ID: 40502435
I have an ASA then a FG then my L3. I can do a VPN split on either the ASA or the FG. I'd choose the ASA as it's efficient and designed to handle a variety of VPNs.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 1

Author Comment

by:leblanc
ID: 40502992
So your ASA is connecting to the main WAN connection and the Internet connection and from the L3 switch, you just have a default route pointed to the ASA. Correct?
0
 
LVL 20

Assisted Solution

by:netcmh
netcmh earned 500 total points
ID: 40503122
Correct. the default route is pointed to the ASA.
0
 
LVL 20

Expert Comment

by:netcmh
ID: 40506856
Thanks for the grade. Good luck.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sonicwall SHA issue 4 40
Stacked switch question 7 41
Home lab datacenter 9 107
TZ400 2 7
In the modern office, employees tend to move around the workplace a lot more freely. Conferences, collaborative groups, flexible seating and working from home require a new level of mobility. Technology has not only changed the behavior and the expe…
A clone is a duplicate copy. Sheep have been cloned and maybe someday even people will be cloned, but disk cloning (performed by the hard drive cloning software) is a vital tool used to manage and protect data. Let’s look at what hard drive cloning …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question