site-to-site fail over.


I got a client with two firewalls at a remote sites. We need to configure site-to-site, so that if one remote firewall fails my VyOS picks up the second peer forms tunnel and forwards traffic.
For example: on Cisco’s ASA I simply can indicate both public peer IPs under the same crypto map entry. The former peer IP will be picked as primary the latter as the backup.

I wonder how I can achieve such setup with VyOS.
thank you.


Hi Felix,
I wonder whether the below is matched with your need or not?

This design can be easily implemented with Vyatta/VyOS.