Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site IPsec as a backup to a fiber Layer 2 transport

Hi All,

I have a question which I posed to Sophos support and was told that the only possible way to do this was with RED tunnels but I would much prefer IPSEC so I thought I would ask.

We have multiple sites in  ahub and spoke topology with primary connectivity between them  being an L2 transport between core switches.

We would like to establish a IPsec tunnel between the two sites as a backup to the L2 transport.

We have found however that if IPsec is active on a UTM that any traffic that hits the UTM uses the IPsec tunnel to the other locations even with OSPF enabled with lower metric.  To throw another wrench in there we have multiple connections to the internet at the hub site which we need to make redundant.

I have read through the forums quite a bit and have found scenarios that are close but not 100%.  The difference being the use of L2 transport terminating at the core switch and not the UTM itself.

I am hoping someone can validate support or offer an alternative.  Thank you in advance!



This thread was automatically locked due to age.
  • "The difference being the use of L2 transport terminating at the core switch and not the UTM itself." Although the new possiblity of binding traffic to a specific local interface does allow you to use routing or Multipath rules to make a redundant connection, there's no possiblity of doing this at layer 2.
    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thank you so much for confirming this Bob!