Support for IPSec Tunnel Failover Planned

Darren White

We would like to be able to specify multiple (or dynamic) endpoint IPs for an IPSec tunnel. This would allow us to create a tunnel to a firewall with 2 WAN connections, so that the tunnel could remain operational using either available WAN IP in case of an ISP outage at our customer location.

Comments

9 comments

  • Comment author
    Eda Ercan
    • Official comment

    Thanks for sharing this request. We've reviewed it and confirmed we're moving forward with IPSec Tunnel Failover as part of the Gateway 14 release in this year's roadmap.

    To make sure the final behavior matches your operational expectations, could you share how you’d like the tunnel endpoints to be defined and what success looks like during failover?

  • Comment author
    Brian D'Arcy
    • Edited

    Seconding this feature request. The ability to have failover IPSEC tunnels (multi-wan to same tunnel subnet/destination) would be a very nice to have feature. We have this implemented for a larger client between their primary office and 3 satellite offices (hardware firewalls), however the remote employees had no connectivity to the main office via Timus for a few days when the primary office had an outage and failed over to their backup connection.

    I can think of 5-6 other clients we have currently on Timus where this type of setup could be beneficial, even though the scenario has yet to come up for them specifically.

    1
  • Comment author
    Roger Curtis

    Yes, this would be a big help for customers with SD-WAN or HA pairs of firewalls, ensuring the Timus IPSec tunnel to that location remains up through any WAN changes or active/passive flipping.

    0
  • Comment author
    Kevin Fagan

    Planned - Will be LIVE with Cloud 1.30.0 and Gateway 14.0.0 Releases - Q3 , 2025.

    0
  • Comment author
    Eric Peterson

    I didn't see this in the release notes for Gateway 14, was this added? 

    0
  • Comment author
    Kevin Fagan

    Eric Peterson - Gateway version 14.0.0 has not been released yet.  It should be out in Q4.

    0
  • Comment author
    Darren White

    Has this been released?

    0
  • Comment author
    Eric Peterson

    Eda, I think the endpoints should be definable by IP or domain name in a primary/secondary format, and success would be that the tunnel between the remote end and Timus gateway is able to fail to the secondary endpoint without manual intervention. 

    0
  • Comment author
    Eda Ercan

    Eric Peterson Thank you for the feedback! This is on our roadmap for this year and we will be sure to keep you informed as progress is made.

    0

Please sign in to leave a comment.