VPN Backup Peer?
Is there any way to specify a backup peer in any way on the 707? I really wish we could just have virtual tunnel interface route-based VPNs, but it appears we're stuck to policy based. Specifically, I have a tunnel to an AWS site to site VPN and would like to be able to setup a backup peer address to the secondary peer in AWS. With Cisco ASAs I remember being able to configure a backup peer, but I can't find any way to do it with TP-Link. Is there any concept to do something like this, or is it always just stuck to a single peer configuration?
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@pdava17752453 AFAIK Omada has only old-fashioned IPSec so no interfaces. It does however support IPSec tunnel groups, where IPSec connections can fail over to a backup tunnel. So if the primary tunnel fails it will connect a fail-over tunnel, and optional fail back to the primary. But it isn't seamless, you wait the DPD time before failover, say 15-20 seconds.
Modern routers support Virtual Tunnel Interfaces (VTI) which effectively enable routing over IPSec rather than just policy. Needless to say, Omada does not support VTI 😭 You might do better to use WireGuard, which Omada supports and is interface based, so you can have prioritized routing tables for backup routes. That means packet-by-packet seamless failover.
- Copy Link
- Report Inappropriate Content
@whereisaaron I was trying to figure out that failover policy page, I suspect it might only be available for managed connections between two TP-Link devices? It just tells me no connections are available for a failover group, and there is no way to add another connection due to the overlap warning, so all I can think of is that feature might be reserved for automatic type connections.
- Copy Link
- Report Inappropriate Content
@pdava17752453 there is supposed to be new firmware coming with SD-VPN easy VPN between sites. However this should work as per this documentation:
https://www.tp-link.com/au/support/faq/3575/
Note that secondary tunnel is in responder mode, as (I think) only changed to initiate during failover.
Wireguard may not be an alternative yet either sorry:
https://community.tp-link.com/en/business/forum/topic/665364
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 39
Replies: 5
Voters 0
No one has voted for it yet.