2. Presume there is only 1 WAN IP at Firewall, hence a NAT need to be carried out at Firewall to map the UDP Port 500 and 4500 to MP2900, and to allow Encapsulation Security Payload (ESP) IPSec protocol number 50 at firewall.
2.2.1 Detail Working Mechanism
1. MP2900 will run dynamic routing RIP when facing internal network. 2. MP2900 will have a static routing to firewall. 3. 2 IPSec tunnel will be build: Tunnel 1 to DC Tunnel 2 to DRC
4. IPSLA will be configure at MP1800 to track the WAN IP of the main link. If the WAN IP is unreachable, the traffic will be switched to the backup VPN tunnel.