Thursday, February 28, 2019

Static w/ SLA vs BGP for redunant VPN setup

I have 2 hub locations with a dozen remote sites over VPNs. Each remote site has a VPN to each hub. Hubs are ASAs and remote sites are Juniper SRX devices.

What's the best way to implement failover in the event connectivity is lost at a hub?

I've never configured BGP before, and I was thinking static routes to each hub with lower metric route tied to SLA to drop it from table in the event it can't be reached.

Thoughts?



No comments:

Post a Comment