Configure IPsec failover
You can configure the EX15 device to fail over from a primary IPsec tunnel to a backup tunnel:
-
SureLink active recovery—You can use SureLink along with the IPsec tunnel's metric to configure two or more tunnels so that when the primary tunnel is determined to be inactive by SureLink, a secondary tunnel can begin serving traffic that the primary tunnel was serving.
-
Preferred tunnel—When multiple IPsec tunnels are configured, one tunnel can be configured as a backup to another tunnel by defining a preferred tunnel for the backup device.
Required configuration items
- Two or more configured IPsec tunnels: The primary tunnel, and one or more backup tunnels.
- Either:
- SureLink configured on the primary tunnel with Restart Interface enabled, and the metric for all tunnels set appropriately to determine which IPsec tunnel has priority. With this failover configuration, both tunnels are active simultaneously, and there is minimal downtime due to failover.
- Identify the preferred tunnel during configuration of the backup tunnel. In this scenario, the backup tunnel is not active until the preferred tunnel fails.