Netscreen Failover question

Netscreen Failover question

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Netscreen Failover question Joris Kemperman 05-11-2005
Posted by Joris Kemperman on May 11, 2005, 11:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hey everyone!

I've got the next situation:

1 mainoffice with one NS 5GT (model 205)
3 branch offices with everyone of them one single NS5GT.

The main office has got two different internetconnections (let's say
connection 1 and 2) and i've setup the NS5GT in the mainoffice to run in
dual-untrust mode, both internetconnections are connected and working on
the
Netscreen. All the branchoffices got one single Internetconnection.

I've setup several route based VPN's:
Branch 1 to Mainoffice
Branch 2 to Mainoffice
Branch 3 to Mainoffice

Now every VPN connection is connecting to the Mainoffice's internet
connection 1. Let's say this connection drops for some reason (ISP
problems), is there a way for me to automaticly let the branchoffices
Netscreens build up their VPN's using connection 2 instead of conncetion 1?

Regards,
Joris


Posted by Munpe Q on May 12, 2005, 6:06 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Try building a second tunnel interface and set a route with a higher
metric using the second tun.x interface as the gateway.
I haven't tried it, but it's logical that it would work.



Similar ThreadsPosted
Reccs for firewall upgrade- small business, 1 remote site, WAN failover- Fortigate vs. Netscreen vs. others? January 25, 2007, 3:46 pm
NetScreen NAT/VPN question April 22, 2005, 12:18 pm
Question about Netscreen 5 GT firewall / VPN March 14, 2005, 3:36 pm
netscreen 25 routing question May 11, 2005, 6:00 pm
Netscreen Passive FTP question September 16, 2005, 9:39 pm
Question about netscreen set policy June 22, 2007, 3:14 pm
Question about IP Summaries on Netscreen firewall June 30, 2007, 6:10 pm
Checkpoint FW1 failover requirements? February 23, 2005, 12:39 am
Cisco ASA 5500 WAN failover September 20, 2005, 7:49 am
Cisco VPN Failover setup May 1, 2006, 5:11 pm

The site map in XML format XML site map

Contact Us | Privacy Policy