Configuring VPN Failover to a Static Route

Optionally, you can configure a static route to be used as a backup route in case the VPN tunnel goes down. The Allow VPN path to take precedence option allows you to create a backup route for a VPN tunnel. By default, static routes have a metric of one and take precedence over VPN traffic. The Allow VPN path to take precedence option gives precedence over the route to VPN traffic to the same destination address object. This results in the following behavior:

When a VPN tunnel is active: static routes matching the destination address object of the VPN tunnel are automatically disabled if the Allow VPN path to take precedence option is enabled. All traffic is routed over the VPN tunnel to the destination address object.
To configure a static route as a VPN failover:
1
Navigate to the Network > Routing page.
2
Scroll to the bottom of the page and click on the Add button. The Add Route Policy dialog is displayed.
3
Select the appropriate Source, Destination, Service, Gateway, and Interface.
4
Leave the Metric as 1.
5
Enable the Allow VPN path to take precedence check box.
6