Friday, September 28, 2018

IPSec Failover design

My company is looking to add a secondary LTE service to use as backup internet at one of our remote locations. We use IPSec tunnels to connect all of our remote sites back to our main location.

We are waiting on equipment to get in to test, but my current plan is this. At the main location simply add the new LTE backup IP as the secondary peerin the crypto map for that tunnel.

My next step is to setup OSPF with the remote vlans and the server vlans. Im hoping that OSPF will handle the routing over the IPSec tunnels back to the main site and dynamically adjust if the primary ever goes down. We don't have too large of a network so Im think we can use a single area for all routers.

I have never done anything like this so my question is will this work? Im worried that the tunnel failing over at the main site may cause issues with OSPF.

Will this setup work, or do you have a better idea?



No comments:

Post a Comment