Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

active/active IPsec with 2 ISPs?

Hi,

is it possible to have an active/active IPsec connection between 2 UTMs (running on 9.3.x)?
Background is that in Site 2 the internet connections from both providers in not very stable...

Site 1:
ISP1: Ext. IP 217.x.x.1 
ISP2: Ext. IP 218.x.x.1

Site 2:
ISP1: Ext. IP 219.x.x.1
ISP2: Ext. IP 220.x.x.1


Could you tell me how to set it up?
I guess I would need active/active uplink balancing and 2 IPsec connections on each site?

Many thanks for your help!


This thread was automatically locked due to age.
Parents
  • Hi Thomas,

    why not only build one tunnel. As SSL. Side 2 is client, side one is server. 

    So, if on side 2 provider 1 fails, the tunnel will be build over provider 2 and vice versa.

    Load balancing over 2 tunnels to the same ip ranges isn't really possible. Two tunnels with the same destination range. How schould a firewall decide witch way it schould take? And takes the answer the same route?

    Viele Grüße / Best Regards,
    Manu

    - CISO -
    - Sophos SCA & Partner-

Reply
  • Hi Thomas,

    why not only build one tunnel. As SSL. Side 2 is client, side one is server. 

    So, if on side 2 provider 1 fails, the tunnel will be build over provider 2 and vice versa.

    Load balancing over 2 tunnels to the same ip ranges isn't really possible. Two tunnels with the same destination range. How schould a firewall decide witch way it schould take? And takes the answer the same route?

    Viele Grüße / Best Regards,
    Manu

    - CISO -
    - Sophos SCA & Partner-

Children
  • Manu, the stimulus for this approach was the desire to prioritize VoIP traffic.  Although you can do much of that with a single tunnel, it's easier to avoid disruption by up/downloads if one set of connections is used for VoIP and the others for everything else.  Adding the fail-over to the other connections was just an extra I did for the client.  We've had no further complaints about VoIP call quality.  In these cases, the VoIP subnets are separate from the data subnets.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA