Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Verify Config - Only use one WAN port for all access, second WAN for P2P VPN Only

I am about to deploy a XG310 on my network to replace two aging TMG 2010 servers.  I just want a verification of settings that I can't find a definitive answer for.

 

We have two "WAN" connections.  One is a 150x150 fiber that we'll call Primary which we use for all internet access and incoming connections (OWA, other websites, client VPN, etc).   The other is a 25x25 fiber that I'll call Secondary which is only used for a IP Sec site to site VPN with a business partner.

 

I want to make sure the secondary connection is never used, not even for failover.  Would the best way to do this be under WAN Link Manager edit the Secondary connection and set it's "Type" to "Backup" then set the "Activate this Gateway" to "Manual"?  I have both using the default NAT policy (MASQ).  Can I leave this like that in this config?  For the IP Sec VPN I have the Secondary port selected as the local endpoint.

 

Any confirmation or suggestions would be helpful.

 

-Allan



This thread was automatically locked due to age.