Re: Failover VPN between sites Rather than maintain 2 firewalls on 2 circuits I think you need to reconsider your architecture. I am not very well versed in the subject of ISP redundancy, but I think the solution you're looking for should be something revolving around this strategy. Make your 2 separate firewalls a single HA cluster. Take the 2 internet circuits and setup ISP redundancy on the cluster rather than 2 individual gateways as you have it now. __________________ There's no place like 127.0.0.1 |