Link to home
Start Free TrialLog in
Avatar of Jorge Diaz
Jorge DiazFlag for United States of America

asked on

Second ISP line question--

Hi there,

so i'm looking to bring another isp line for backup purposes. because of budget constraints we're thinking about configuring another firewall's interface for with new new circuit settings and configure the fw for failover in the event the main connection goes down.

Our network has gotten a little bit more technical over the years and now we have a lot of users connecting to the vpn using cisco anyconnect, some users access office resources (with split tunnel)  and others to access cloud resources that white list our ip address (they use tunnel all).

I know outbound traffic will work seamlessly if the even of fail over but i'm thinking in terms of incoming traffict:

There are few items i still don't wrapt my head around, such as vpn access -- i assume we'd need to configure another dns A record with the new IP and add a different weight.
what about the certificate? do i need to generate a new certificate to reflects both ip address to the same dns name?

is there anything else i'm missing here?

thanks for your help.
ASKER CERTIFIED SOLUTION
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Jorge Diaz

ASKER

it's a 5516-x,

so same cert on both interfaces or i'd need a new cert?

thanks
Spot on!

You simply enable the same certificate for the new ISP interface :)

Pete