Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VPN as an bandwidth enhancement to private MPLS with failover

Following situation:

I want to share network load between our MPLS links and Internet-VPNs.

For this I've created a test scenario.

One Firewall Cluster in Germany, the other one in Spain.

Two VPNs, one over Internet, one over MPLS. Bound to local interfaces.

I've created two interface groups Internal+External and External+Internal, first with Internal interface at the top, the other vice versa.

VPNs are up and I can route traffic to one server in Germany over the Internet-VPN and to another server over the MPLS-VPN with Police Routing and the created interface groups.

 

The question is: does this failover in both directions?

If Internet links is down, so the Internet VPN, will all traffic will be routed via MPLS and vice versa?

 

Multipath Rules, depending on Uplink monitoring is not possible, because the MPLS network is just internal, no Internet behind this.

 

Any suggestions?

 

We are planning to implement iWAN from CISCO which does the routing automatically, based on bandwidth and request times, and with QoS, too.

Until end of this project I want to test this because we have some bandwidth problems on MPLS.

 

One additional thing: we cannot use OSPF.



This thread was automatically locked due to age.
  • See Sophos UTM multiple S2S IPsec VPN mit Failover – Tutorial (DE) in the UTM Wiki.  I think the approach you're using to bind the non-MPLS VPN to the External interface will allow you to have instantaneous auto-failover without using a VPN over MPLS.  Static Routing should work for all of this.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • With Multipath Rules? I want to use Policy Based Routing. Depending on local/remote IP or TCP ports.

     

    This does not work with objects other than local Interfaces, right?

  • Yes, use Policy Routes.  My point was that you don't need to create a VPN through the MPLS connection in order to use Static Routes with that connection.  I only linked you to that Wiki article because it discusses some of the issues you need to have in mind - not a prescription for you, just background reading.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA