Zyxel ZyWALL USG 20 [119/185] Ipsec vpn fail over and fall back

Zyxel ZyWALL USG 20 [119/185] Ipsec vpn fail over and fall back
ZyWALL USG Support Notes
119
All contents copyright (c) 2010 ZyXEL Communications Corporation.
fall back (built to) the HQ USG WAN1 again.
4.2. IPSec VPN Fail Over and Fall Back
4.2.1. Application Scenario
In the below enterprise network, HQ has two WAN connections. WAN1 is connected
to internet while WAN2 is connected to a leased line. Branch office 1 requires a
secured connection to HQ with minimum failure time. We can deploy IPSec VPN HA
to meet Branch office 1‟s requirement.
However, since HQ WAN2 is connected to a leased line, it cannot be reached from
internet, making building VPN tunnel from Br1 to HQ‟s WAN2 not possible. Branch
office 2‟s WAN2 is also connected to the leased line. Br2 can reach HQ WAN2. We
can use Br2 USG to route VPN traffic from Br1 to HQ. Once HQ WAN1 is done, Br1
can first build a tunnel to Br2 WAN1. Then Br2 WAN2 builds a tunnel to HQ WAN2.
Traffic from Br1 to HQ can first go to Br2 through VPN tunnel, then go to HQ
through the other VPN tunnel from Br2 to HQ.
We can enable HA Fall Back. Once HQ USG WAN1 is up again, Br1 can build tunnel

Содержание

Похожие устройства

Скачать