Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Failover criteria for route based VPN

$
0
0

For route based tunnel failover you are best to use a dynamic protocol instead of static routes.  Static routes will remain active in the route table as long as the next hop interface is up.  And by default these tunnel interfaces stay up even when vpn connectivity goes down.

 

By using a dynamic profile you avoid this problem because the routes will be lost when the neighbor is lost due to the tunnel going down and your failover can kick in.

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>