Hello All,
I have a question on the two vpn tunnels between the same site.
There is an existing tunnel between the sites and it is working fine.
Peer 1
======
tunnel.4 (VPN1 Zone)
outgoing interface - ethernet1/1 (Trust Zone)
Source Subnets to be encryped - 172.16.100.0 and 172.16.101.0
Destination subnets for this VPN - 172.16.95.0 and 172.16.93.0
Route to peer vpn subnets - tunnel.4
Peer 2
=====
Tunnel.1 (Trust Zone)
Outgoing Interface - ethernet0/0 (Untrust Zone)
Source Subnets to be encryped - 172.16.95.0 and 172.16.93.
Destination subnets for this VPN - 172.16.100.0 and 172.16.101.0
Default route - tunnel.1
Now I have to create a new tunnel between the same sites for DR purposes. My question here will the Netscreen SSG allow me to create a new tunnel between the same sites when the source subnets are identical with the existing VPN tunnel. Peer 2 already has a default route pointing to tunnel.1 (includes the destination subnets for the new tunnel), how can I create route for the new tunnel. Both these tunnels will be sending traffic
Peer 1
======
Create a new tunnel interface - tunnel.5 (unnumbered interface)
Outgoing interface - ethernet1/1
Source Subnets to be encryped - 172.16.100.0 and 172.16.101.0 (same source subnets as existing tunnel)
Destination subnets for this VPN - 172.16.99.0
Route to peer vpn subnets - tunnel.5
Peer 2
=====
Tunnel.2 (Trust Zone)
Outgoing Interface - ethernet0/0 (Untrust Zone)
Source Subnets to be encryped - 172.16.99.0
Destination subnets for this VPN - 172.16.100.0 and 172.16.101.0 (same destination subnets as existing tunnel)
Route to destination vpn subnets - tunnel.5 (But default route already pointing to tunnel.1 for existing tunnel)
Your help will be greatly appreciated.
Thanks
Sidhanth