Hi,
I want to fail my ipsec tunnels across dual ISPs.
I have dual ISP interfaces set on my test box, have set up an interface group which includes them both. I then set up a new site to site ipsec tunnel using the interface group rather than a physical int as the local interface. According to the documentation (KB #118975) you shoud then tick 'bind tunnel to local interface' - it says "If one of the two created interfaces is down or has an error the other will directly take over" - that's exactly what I want ... but ... I click 'save' and get "Cannot bind tunnel to uplink interface or interface group" I've tried setting the dual ISP ints as both uplink interface and interface group, get the same message. It's fine with the single physical int, of course. Is the documentation just wrong? Any help appreciated. UTM - 9.312-8
This thread was automatically locked due to age.