Originally posted by: spidey07
Sorry to hear.
I don't believe it can. IPsec has to verify the endpoints of the tunnel.
I'm not sure though.
So you have two pixes on one side running HSRP? And that is the endpoint of some tunnels - a HSRP enabled interface?
Originally posted by: spidey07
well then if it isn't a in a failover mode (meaning the other pix is fully licensed and not a redundancy pair), you could just move some of the tunnels over to the other pix. At that point your routing would be responsible.
But now that I think about it, this is a mix of routing and your tunnels. Without having a full diagram and knowing the routing its difficult to guess what would happen.
We need a dang whiteboard.
Originally posted by: cross6
we need to create new vpn connections - and we them to go through the secondary pair
Originally posted by: spidey07
Originally posted by: cross6
we need to create new vpn connections - and we them to go through the secondary pair
Make new VPN tunnel to secondary pix.
Add static route (for the far end network on the other side of the tunnel) on primary HSRP router to point to secondary HSRP router "real" ip address.
That will do what you require with little change/configuration. Do backup all configs of all devices before doing so though. That way it will be easy to get to the state you are at today.
