Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPsec Routed-Based VPN - How to config static routes or SD-WAN rules with failover tunnels

Hello.

I have 2 sites with 2 ISP each other: Site 1 (ISP A, ISP B), Site 2 (ISP X, ISP Y). So I think to config 4 tunnels like we did with Site-to-Site IPsec VPN:

Tunnel A-X, Tunnel A-Y, Tunnel B-X, Tunnel B-Y.

Site 1 publish this networks (192.168.10.0/24, 192.168.20.0/24, 192.168.30.0/24). Site 2 publish this networks (192.168.60.0/24, 192.168.70.0/24)

xfmr interfaces:

Site 1 ------------------------------ Site 2

AX: 10.1.0.1/30 ----------------- AX: 10.1.0.2/30

AY: 10.2.0.1/30 -----------------  AY: 10.2.0.2/30

BX: 10.10.0.1/30 --------------- BX: 10.10.0.2/30

BY: 10.11.0.1/30 --------------- BY: 10.11.0.2/30

Now how must I config same routes with different gateways??



This thread was automatically locked due to age.
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    You need to create a custom gateway with xfrm tunnel interface at both ends.

    Here are the sample snapshots for reference.

    Then, create an SD-WAN policy route with required source & destination networks, and select primary & backup gateway as custom gateways.

    A similar configuration needs to be done at SiteB.

  • Hello Thank you for  your answer!!

    What about with routes from "ISP B"?  this will be SAME that routes for "ISP A" with diferent gateway. And in SD-WAN policy we can only add one backup gateway.

    I have no problem with config traditional Site-to-Site IPsec tunnels, only want to try this new feature.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?