Configure Firewalls to failover to a backup VPN Route when the MPLS Fails
I have 9 offices connected to a main office with MPLS. The main office has NSA 3600 the remote offices have a mix of TZ500 & TZ400's. Each office has a separate internet connection as well. I would like to be able to set the firewalls up so if there is a MPLS failure the VPN connection can take over and handle the traffic until the MPLS is back online. I am trying to test with 1 remote site, The MPLS route has already been configured for the main & remote officce. I have now configured a VPN Tunnel connection on both the remote & main site Sonicwalls and it created the interface and the route and is showing as up. I have configured the metric with MPLS a 2 VPN 20 I had the remote site take down the MPLS and the VPN connection did not take over.
In further googling I found that I should create a probe on the MPLS route to bring the MPLS down when the probe detects it is offline. I believe I have that setup but cannot test it now. Is there anything else I should check or need to configure? I feel like I am missing something I did see some traffic out but not in on the remote site sonicwall over the tunnel when we took the MPLS down
Thanks!
Answers
Probing is only part of it, start looking into policy based routing to actually handle the routing logic after a probe fails. Some articles to help:
Depending on how you configured your MPLS interface, you could also use SD WAN policies.
Hi @ChrisLakeErie,
Thank you for visiting SonicWall Community.
The configuration on the below KB article is something that you are looking for. Please go through the same and it should match your requirement.
Please feel free to post for any questions/clarification.
Regards
Saravanan V
Technical Support Advisor - Premier Services
Professional Services
Saravanan! Thank you for this it looks like exactly what I need support sent me a different article that got me almost there but this is my scenario! I will try setting this up shortly.
Hi @CHRISLAKEERIE,
Great!!!
Please configure the SonicWalls and hopefully you would be in a better position with your requirement.
Regards
Saravanan V
Technical Support Advisor - Premier Services
Professional Services