1/2
SSL VPN redundancy?

Franklin Lv1Posted 2026-Aug-22 03:48

Hello.

I have a question: is there any way to add redundancy to the Sangfor SSL VPN? In other words, if one of my ISP's connections goes down, can it automatically start receiving connections through another ISP's connection?

Prosi has solved this question and earned 20 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi,

Yes. Sangfor can be configured to ensure that the SSL VPN endpoint remains accessible via the secondary ISP; however, there are significant differences between outbound WAN failover and inbound SSL VPN failover.

Sangfor's SSL VPN documentation describes implementing gateway mode with dual WAN paths, and the latest Sangfor NGAF documentation supports the use of multiple WAN links, as well as link load balancing and failover features.
Is this answer helpful?
Muhammad Abid Lv3Posted 2026-Aug-22 11:55
  
Yes — Sangfor NGAF can provide WAN redundancy/failover, but there is an important distinction for SSL VPN.

If your setup is:

ISP-1 → Sangfor NGAF → Internet/SSL VPN users
ISP-2 → Sangfor NGAF → Internet/SSL VPN users

then Sangfor can monitor the WAN links and use the secondary WAN when the primary fails. Sangfor documentation/community confirms multi-WAN failover and backup-WAN support.

For your SSL VPN specifically

The challenge is the public IP.

For example:

ISP-1 public IP = X.X.X.X
ISP-2 public IP = Y.Y.Y.Y
Users normally connect to https://X.X.X.X:443

if ISP-1 goes down, the existing SSL VPN connection to X.X.X.X cannot simply continue through ISP-2, because X.X.X.X is no longer reachable.

You need a mechanism that gives users an alternative reachable endpoint, such as:

Option 1 — Sangfor Intelligent Link Selector / multiple VPN gateways
Sangfor's community documentation describes an Intelligent Link Selector for SSL VPN when multiple links are available.

Option 2 — DNS-based failover
Users connect to something like:

vpn.company.com

and DNS can point to ISP-1 normally and ISP-2 when ISP-1 fails. The user may need to reconnect.

Option 3 — Sangfor SD-WAN/WANO approach
Sangfor supports multiple WAN links with automatic path selection and failover for VPN tunnels.

Important

If your requirement is:

"ISP-1 fails → SSL VPN users automatically reconnect through ISP-2 without changing anything."

Then yes, redundancy is possible, but simply configuring WAN load balancing is not enough. You need to design the SSL VPN access/failover mechanism as well.

If you tell me your Sangfor NGAF model + firmware version + how your 2 ISP connections are currently connected, I can give you the exact recommended topology and configuration for SSL VPN failover.

Moneeb Lv3Posted 2026-Aug-22 12:17
  
No. You have to provide the user backup IP (IP of the other ISP) to connect the SSL VPN from start, if the primary ISP connection goes down.
Prosi Lv4Posted 2026-Aug-22 17:31
  
Hi,

Yes. Sangfor can be configured to ensure that the SSL VPN endpoint remains accessible via the secondary ISP; however, there are significant differences between outbound WAN failover and inbound SSL VPN failover.

Sangfor's SSL VPN documentation describes implementing gateway mode with dual WAN paths, and the latest Sangfor NGAF documentation supports the use of multiple WAN links, as well as link load balancing and failover features.
Muhammad Abid Lv3Posted 2026-Aug-22 19:05
  
Yes. Sangfor SSL VPN supports multi-WAN / multi-line configuration, so you can connect two ISP links and configure the second ISP as a backup. Sangfor documentation specifically describes multiple Internet lines and automatic line selection for SSL VPN.

Your scenario

For example:

                 ISP-1 (Primary)
                      │
                 WAN 1 │
                      ▼
              ┌────────────────┐
              │ Sangfor SSL VPN│
              │                │
              │ Multi-Line     │
              │ / Failover     │
              └────────────────┘
                      ▲
                 WAN 2 │
                      │
                 ISP-2 (Backup)

You can configure:

WAN1 → ISP-1 → Primary
WAN2 → ISP-2 → Backup
Enable SSL VPN Multi-Line
Configure the public IP of both Internet connections.
Enable line/health detection where supported.

When ISP-1 fails, Sangfor can select the other available Internet line. The official manual states that Multi-Line allows multiple Internet lines and can automatically select an optimal line when users log in to SSL VPN.

Important point

There is a difference between new VPN connections and an already-established VPN session.

If a remote user is already connected through ISP-1 and ISP-1 suddenly goes down, the existing SSL VPN session may disconnect and the user may need to reconnect. The backup ISP then allows the VPN connection to be established through WAN2.

So it is better to think of it as:

ISP-1 Down → WAN2 becomes available → user reconnects automatically/manually depending on client behavior.

If you want seamless HA where an existing VPN session survives an ISP failure, that is a more advanced design.

If you tell me your Sangfor model and firmware version (for example, SSL VPN M5100/M5200 and version), I can give you the exact menu-by-menu configuration for WAN1/WAN2 failover.
Korchai Lv2Posted 2026-Aug-23 18:57
  
No. In the event that the primary ISP connection fails, you must supply the user backup IP (IP of the other ISP) in order to connect the SSL VPN from the beginning.
James Sibala Lv1Posted 2026-Aug-24 13:56
  
Yes. can be configured to ensure that the SSL VPN endpoint remains accessible via the secondary ISP; however, there are significant differences between outbound WAN failover and inbound SSL VPN failover.

Sangfor's SSL VPN documentation describes implementing gateway mode with dual WAN paths, and the latest Sangfor NGAF documentation supports the use of multiple WAN links, as well as link load balancing and failover features.
AR Lv3Posted 2026-Aug-24 19:34
  
Hello

Indeed, Sangfor can be set up to guarantee that the SSL VPN endpoint is still reachable through the backup ISP; however, outbound WAN failover and inbound SSL VPN failover differ significantly.

The most recent Sangfor NGAF documentation enables the usage of multiple WAN links along with link load balancing and failover functionality, while Sangfor's SSL VPN documentation explains how to implement gateway mode with dual WAN pathways.
Newbie900829 Lv1Posted 2026-Aug-26 01:11
  
Hi there,

Although outbound WAN failover and inbound SSL VPN failover are very different, Sangfor can be configured to ensure that the SSL VPN endpoint is still reachable through the backup ISP.

While Sangfor's SSL VPN documentation describes how to implement gateway mode with dual WAN channels, the most recent Sangfor NGAF documentation permits the use of multiple WAN lines together with link load balancing and failover capability.

I Can Help:

Change

Moderator on This Board

1
157
3

Started Topics

Followers

Follow

1131
242
101

Started Topics

Followers

Follow

Board Leaders