IPSec VPN Backup

Blackhole route
Last updated
FGT1 # show router static
config router static
edit 2
set device "ike2" --> default distance is 10
set comment "VPN: ike2 (Created by VPN wizard)"
set dstaddr "ike2_remote"
next
edit 3
set distance 254
set comment "VPN: ike2 (Created by VPN wizard)"
set blackhole enable
set dstaddr "ike2_remote"
next
edit 8
set distance 15 --> higher distance for backup tunnel
set device "ike2_backup1"
set comment "VPN: ike2_backup1 (Created by VPN wizard)"
set dstaddr "ike2_backup1_remote"
next
edit 9
set distance 254
set comment "VPN: ike2_backup1 (Created by VPN wizard)"
set blackhole enable
set dstaddr "ike2_backup1_remote"
next
end