Network tunnel groups organize IPsec tunnels from supported network devices so traffic can connect securely to Secure Access through shared regional hubs. They provide redundant, highly available tunnel connectivity by pairing tunnels with primary and secondary data center hubs that can be monitored and managed as a group.
Tunnels and tunnel groups are core concepts in managing connections between your data centers and Cisco Secure Access. Supported network devices capable of establishing an IPsec tunnel can join a network tunnel group.
-
Secure Access enables fast, reliable, and secure private network connections to your applications through IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnels.
-
Network devices that are capable of establishing IPsec tunnels forward traffic to one of the Secure Access data centers where the tunnel head end is located.
-
User devices can read, write, and update private resources by setting up virtual private networks (VPNs) or zero trust access (ZTA) connections to Secure Access through these IPsec tunnels.
-
A network tunnel group provides the framework for establishing tunnel redundancy and high availability. Connect tunnels to the hubs within a network tunnel group to securely control user access to the internet and private resources.
Provisioning high-availability network tunnel groups at a hub site allows a group of tunnels to share a primary and secondary hub. Each data center hub in a network tunnel group can connect to multiple tunnels. A hub configured for NAT can support up to 100 tunnels. A hub that is not configured for NAT is limited to 10 tunnels.
Failover for Branch Connections in Secure Access Data Centers
For high availability, customer branch devices must connect to both the primary and secondary hubs in Cisco Secure Access data centers. They must have tunnel auto-reconnect enabled on the branch device and have a failure detection mechanism like Dead Peer Detection (DPD), IP SLA, or BGP timeout, depending on their use case. If you configure only a primary tunnel, you will experience interruption of service during regular maintenance windows or unplanned outages.
Under normal conditions, traffic flows through the primary data center. If the primary data center fails, traffic routes through the secondary data center. Switchover time depends on the nature of the primary tunnel failure and various timers.
Primary traffic failover to secondary can occur instantaneously if the Secure Access or customer branch device initiates and successfully terminates the IKE tunnel or BGP session.
Terminating the IKE tunnel also terminates BGP.
In cases of communication failure between the branch device and Secure Access, traffic switches to the secondary only under the following conditions:
-
The Secure Access side DPD timeout occurs or the BGP hold timer expires.
-
The customer's DPD timeout is not effective in this situation because it does not result in tunnel termination on the Secure Access side.
-
The shorter of the Secure Access DPD timeout (156 seconds maximum; default and non-negotiable) and the BGP hold timer (90 seconds; default and negotiable) applies. For example, with a DPD timeout of 156 seconds and a BGP hold timer of 90 seconds, it takes at least 90 seconds for traffic to switch to the secondary tunnel.
Recommendations
-
Initiate a tunnel termination when a traffic failure is detected through the primary tunnel.
-
If initiating a tunnel termination is not feasible, terminate the BGP session or wait for the BGP hold timer to expire.
-
Configure the DPD timeout for your organization to match the Secure Access DPD timeout (156 seconds maximum). For example, 1 DPD every 30 seconds with 4 retransmits before failure: 30 seconds × 5 DPD = 150 seconds delay.