Hello,
I was wondering, if I would create a tunnel from spoke site to a 3rd party that is advertising 2x any casted IP addresses over a tunnel.
However to make some sort of redundancy I would need to create a second VPN tunnel from same site to a different device of the 3rd party to get the same 2x IP addresses advertised over there, and then use a script that tracks the tunnels and swaps over.
This would mean I have to maintain the scripts and update and possibly monitor the outputs from the scripts.
I was thinking as a possible solution to create a tunnel from the regional hub site (one armed VPN concentrator) to the 3rd party and receive there a /30 advertisement for these same 2 IP's so I would have 2x routes to the IP's 2x /32s and 1x /30.
My question is, if the spoke site tunnel goes down, will the site MX see the /30 route and route it to the hub and through there without any intervention, same for when tunnel comes back up will it move it back as now there is more specific ?
Could I have 2x tunnels to the 3rd party provider from the spoke site and receive both IP over the tunnel and when one tunnel goes down, update the routing table to use the other tunnel ?
I am a little bit confused how the routing table in regards to VPN functions on the Meraki devices.
Maybe as a bottom line, any other scenarios or ways to have redundancy for a service that is behind a 3rd party tunnel other than tag based IPsec VPN Failover ?
https://developer.cisco.com/meraki/explore/tag-based-ipsec-vpn-failover/