How can I use a VPN with a network redundancy solution?
In order to setup a VPN connection through a network redundancy router, the following requirements must be met:
- Dynamic IP VPN in “Aggressive Mode”
- IKE Keepalives set to occur fairly often (every 30 seconds recommended)
- Dead peer detection enabled (if available) and set for three misses over 180 seconds or less
VPN Operation:
By configuring VPN in this manner it will work 100% in failover mode (as long as dead peer detection is enabled). It will also work in load balancing mode, however it may occasionally timeout and need to re-sync (reset the SA or Security Association). This is accomplished via the dead peer detection process mentioned above. This re-syncing should not occur very often, and will not as long as the keepalives are set to a low number.
If your VPN does not support NAT pass-through the VPN will NOT work on failover. It is recommended that a NAT enabled VPN solution is used.
If dead-peer detection is not enabled, then manual intervention when a network failure occurs is required.
XRoads Networks = Unified Bandwidth Management with Internet Bonding
This blog, developed by XRoads Networks is designed to assist organizations in learning about the many benefits of MultiWAN deployments and UBM solutions. This blog's aim is to assist end-users understand how UBM works, why it is the most cost effective method for improving speed and responsiveness in todays congested networks, with real-world examples.
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home