We have configured redundancy with 2 ISP. Both ISP's have given us a Primary IP, and an additional subnet. ISP1 is the Active, and ISP2 is the Standby interface. The additional subnet are added to the Interface as additional ip addresses.
NAT (Masquerade) is "Uplink Interfaces" for one Network, And an Additional Ip Address from each ISP to each of the other networks.
The VPN tunnel source is set to UPLINK interfaces, and the Remote router is also configured with backup tunnel. The issue is that although with both ISP's the Tunnel SA is established, the primary isp is not letting traffic reach the remote subnet. If we use the secondary ISP, tunnel traffic is allowed. The Local Network for the Tunnel is a Network, which is using a Masquerade to one of the Additional Ip's of each ISP. All services failover perfectly. We cannot understand why with the connection of one ISP, traffic to the remote tunnel is blocked, and with the other not.
I hope I managed to explain the setup clearly.
Thanks
Josef
This thread was automatically locked due to age.