Forum Discussion
load balance vpn tunnels
Hi community- I have 2 pair of 4000 ltm/gtm/apm. I would like to load balance a vpn tunnel or two in active standby pair, with a site to site vpn tunnel. Will this be possible on 11.5?
5 Replies
- Mahmoud_Eldeeb_
Cirrostratus
would you like to terminate IPSec traffic at BIG-IP, or to IPSec traffic will pass-through BIG-IP ?
- wwalla_99196
Nimbostratus
Ipsec traffic will terminate on the f5 with an asa on the inside passing the traffic to the inside core. Imagine our 4k ltm/gtm dual isp vpn tunnels terminating at a 3rd party site. We would like our outbound connections to this 3rd party site to be load balanced or at least failover to the 3rd party.
- Mahmoud_Eldeeb_
Cirrostratus
Also there is a white paper it might help http://preview.f5networks.net/pdf/white-papers/microsoft-direct-access-white-paper.pdf
- Donald_Endres_2
Nimbostratus
I am in a similar situation. I have 2 ipsec tunnels over different carriers terminated by bigip and cisco asa. With the traffic-selector abstraction, there does not seem to be a way to monitor and score tunnels for an active/standby configuration or load balancing. I have not been able to successfully use "ipsec-policy" "mode interface". Any recommendation would be greatly appreciated.
- Philip_Tan_1205Historic F5 Account
Were you able to receive an answer to this question?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com