VPN Backup Peer?

VPN Backup Peer?

VPN Backup Peer?
VPN Backup Peer?
23 hours ago
Tags: #VPN
Model: ER707-M2  
Hardware Version: V1
Firmware Version: 1.2.3

Is there any way to specify a backup peer in any way on the 707? I really wish we could just have virtual tunnel interface route-based VPNs, but it appears we're stuck to policy based. Specifically, I have a tunnel to an AWS site to site VPN and would like to be able to setup a backup peer address to the secondary peer in AWS. With Cisco ASAs I remember being able to configure a backup peer, but I can't find any way to do it with TP-Link. Is there any concept to do something like this, or is it always just stuck to a single peer configuration?

  0      
  0      
#1
Options
5 Reply
Re:VPN Backup Peer?
18 hours ago
  0  
  0  
#2
Options
Re:VPN Backup Peer?
18 hours ago
Not quite, forcing it to responder mode won't work for me, and I have separate PSKs to deal with on each peer IP. VTI support is what would really work best, too bad it doesn't seem like any TP-Link devices support it.
  0  
  0  
#3
Options
Re:VPN Backup Peer?
an hour ago

@pdava17752453 AFAIK Omada has only old-fashioned IPSec so no interfaces. It does however support IPSec tunnel groups, where IPSec connections can fail over to a backup tunnel. So if the primary tunnel fails it will connect a fail-over tunnel, and optional fail back to the primary. But it isn't seamless, you wait the DPD time before failover, say 15-20 seconds.

 

Modern routers support Virtual Tunnel Interfaces (VTI) which effectively enable routing over IPSec rather than just policy. Needless to say, Omada does not support VTI 😭 You might do better to use WireGuard, which Omada supports and is interface based, so you can have prioritized routing tables for backup routes. That means packet-by-packet seamless failover.

 

 

 

  0  
  0  
#4
Options
Re:VPN Backup Peer?
an hour ago

  @whereisaaron I was trying to figure out that failover policy page, I suspect it might only be available for managed connections between two TP-Link devices? It just tells me no connections are available for a failover group, and there is no way to add another connection due to the overlap warning, so all I can think of is that feature might be reserved for automatic type connections. 

  0  
  0  
#5
Options
Re:VPN Backup Peer?
33 minutes ago

@pdava17752453 there is supposed to be new firmware coming with SD-VPN easy VPN between sites. However this should work as per this documentation:

 

https://www.tp-link.com/au/support/faq/3575/

 

Note that secondary tunnel is in responder mode, as (I think) only changed to initiate during failover.

 

Wireguard may not be an alternative yet either sorry:
https://community.tp-link.com/en/business/forum/topic/665364

  0  
  0  
#6
Options