Version:

Version:


Table of Contents

New Features

Download PDF
Copy Link

FGSP per-tunnel failover for IPsec 7.0.8

During FGSP per-tunnel failover for IPsec, the same IPsec dialup server configured on each FGSP member may establish tunnels with dialup clients as the primary gateway. The IPsec SAs are synchronized to all other FGSP peers that have FGSP synchronization for IPsec enabled. Other FGSP members may establish a tunnel with other clients on the same dialup server and synchronize their SAs to other peers.

Upon the failure of the FGSP member that is the primary gateway for a tunnel, the upstream router will fail over the tunnel traffic to another FGSP member. The other FGSP member will move from standby to the primary gateway for that tunnel and continue to forward traffic.

For more information about this feature, see FGSP per-tunnel failover for IPsec.

Note

This topic uses config system standalone-cluster to configure the FGSP peers. In FortiOS 7.0, the peers are configured using config system standalone-cluster and config system cluster-sync.

FGSP per-tunnel failover for IPsec 7.0.8

During FGSP per-tunnel failover for IPsec, the same IPsec dialup server configured on each FGSP member may establish tunnels with dialup clients as the primary gateway. The IPsec SAs are synchronized to all other FGSP peers that have FGSP synchronization for IPsec enabled. Other FGSP members may establish a tunnel with other clients on the same dialup server and synchronize their SAs to other peers.

Upon the failure of the FGSP member that is the primary gateway for a tunnel, the upstream router will fail over the tunnel traffic to another FGSP member. The other FGSP member will move from standby to the primary gateway for that tunnel and continue to forward traffic.

For more information about this feature, see FGSP per-tunnel failover for IPsec.

Note

This topic uses config system standalone-cluster to configure the FGSP peers. In FortiOS 7.0, the peers are configured using config system standalone-cluster and config system cluster-sync.