Brief:
At the branch site, we use the FortiGate firewall master and slave to establish VPN site to site with HQ. At HQ, there are two small locations, each location placed one firewall and backup together. To backup for link internet from the Branch site to ISP, we must deploy two links with two different ISP. Each ISP provides one public IP address. For each IP address, we set up two Ipsec VPN links from Branch’s firewall to two firewalls at HQ. For each public ip address of Branch’s firewall, we configure one Aggregate link include two tunnel links established with two firewalls at HQ site. To perform backup link and device, we need configure link monitor on Firewall FortiGate.
- Project Name:
- Fail Over IPSec Site-to-Site VPN with redundant link on FortiGate Firewall
- Description:
-
Fail Over IPSec Site-to-Site VPN with redundant link
- Key Configuration:
- Setup connection, ip address, dhcp, routing ospf on the Firewall and router, Configure failover master, slave between two firewalls FW-Campus-Master and FW-Campus-Slave, Configure routing OSPF between two FortiGate Firewall and Router Backbone at HQ with bfd under ospf for high availability and distribute-list deny default-route learned via OSPF together, Configure link-monitor internet gateway on each firewall to track default static route, Configure VPN aggregate link include two members tunnel links as above to redundancy.