MULTI WAN TECHNICAL OVERVIEW The Multi WAN feature will allow the service provider to load balanced all client TCP and UDP traffic only. It also provides redundancy for HA. Traffic that is load balanced: 1. User traffic (TCP and UDP only) Traffic that is not load balanced: 1. User traffic that is not TCP and UDP. e.g. ICMP 2. Traffic generated from the gateway itself. e.g. DNS, SMTP, syslog 3. Static routes configured under Network > Static Routes 4. User subnet that is being configured to bypass under Network > WAN > Load Balancer > Bypass Source IP Subnet 5. WAN Interface and WAN Interface 2 subnet Physical Port Multi WAN uses port OPT 2 for WAN interface 2. Below are the physical locations on each InnGate model: E Series (InnGate 3.00) Back Panel Page 1 of 12
Advanced Network Technology Laboratories Pte Ltd E Series (InnGate 3.01) Back Panel G Series (3.01) Back Panel Configuring 2nd WAN Interface You can configure the 2nd WAN interface from Admin GUI under Network > WAN. You can also change the default route to the 2nd WAN interface. Page 2 of 12
Note: All traffic that is not load balanced will be routed out via the default interface. Configuring Load Balancing After configuring the 2 nd WAN Interface, enable Load Balancer to support load balancing. Under Network > WAN > Load Balancer, check on the option Enable Load Balancer and check on the WAN Interface to include for Load Balancing (WAN Interface, WAN Interface 2). Page 3 of 12
Configure the weight to determine how the gateway will load balance the user s traffic. Interface with higher weight will get more users or connections assigned to it based on the algorithm chosen. The algorithms of load balancing affects how user s traffic is load balanced. Weighted Least Connections: Weighted Round Robin: Connections will be assigned to each WAN Interface according to the weight Each client will be assigned to WAN interface according to the weight Page 4 of 12
Configuring 2 nd DNS to route out through WAN Interface 2 Configure the 2 nd DNS server to route out through WAN Interface 2, so that if WAN Interface 1 is down, DNS resolution will continue to work. From Network > Static Routes, add the new entry for DNS routing. Page 5 of 12
Configuring Web Proxy If you use web proxy, configure the 2 nd proxy to route out through WAN Interface 2. Page 6 of 12
From Network > Static Routes, add the new entry for proxy routing. Page 7 of 12
Configuring Bypass Bypass Source IP Subnet To bypass load balancing based on Source subnet, configure it at Network > WAN > Load Balancer > Bypass Source IP Subnet. It may be necessary to bypass load balancing for public IP address. Destination Bypass Subnet via Static Routes To bypass load balancing based on destination, configure a static route entry. Page 8 of 12
Reports Check the current state of the Load Balancer under Reports > Monitors > Load Balancer. The following information is available in the main summary: Interface Status Weight Packets Octets PPS Rate Total Connections CPS Active Inactive Persistent WAN Interface Up / Down / Disabled Weight assigned to Interface Number of packets processed by the Interface since the last restart Volume of data processed by the Interface since the last restart Packets per second Traffic volume per second Cumulative number of connections established since restart Connections per second TCP connections that are established TCP connections in other state and UDP connections Number of users on this interface Page 9 of 12
Detailed Report Persistent Connections Interface IP address Expiry WAN Interface user traffic is going out from User s IP address Expiry time of persistent connection Detailed Report Connections Interface IP Address:Port Destination:Port Expiry Protocol State Status Outgoing WAN Interface (translated if NAT is enabled) IP address of client and port Destination IP address and port Expiry time of connection. Decreases when there is no traffic TCP / UDP Current state of connection (ESTABLISHED, FIN_WAIT, UDP) Status of connection (Active / Inactive) Page 10 of 12
Page 11 of 12
FAQ 1. Q: Is the Multi WAN module available for all types of InnGate? A: Currently it s only available for E Series and G Series. Purchase of the activation module is required to activate this feature. 2. Q: After I activated Multi WAN, what will happen if the WAN Interface 2 link is down? A: InnGate has the probing mechanism to detect whether the link is up or down. When one of the WAN interfaces is detected down, the traffic will be failover to the other WAN interface which is up. 3. Q: How can I check which device goes to WAN interface or WAN interface 2? A: Go to Admin GUI s Reports > Monitors > Load Balancer under Persistent Connections. 4. Q: How does the load balancer s probing mechanism work? A: For each of the enabled interface, the probing mechanism arpings each interface's gateway IP. If there is a reply, that interface is immediately marked as up. Else, another arping is repeated again 10s later. The interface will be marked as down after a total of 3 unreplied arpings (max 30s). This probing happens every 1 minute. 5. Q: How is the bandwidth allocation for Multi tier QoS in regards to Load Balancer s weight? A: The total bandwidth allocation will be divided based on the weight of Load Balancer for each WAN interface. For example: Total Bandwidth WAN Interface (weight: 2) WAN Interface 2 (weight: 1) Download Upload Upload Download Upload Total 5 Mbps 2 Mbps 1365 Kbps 5 Mbps 682 Kbps GBT 1 1 Mbps 512 Kbps 341 Kbps 1 Mbps 170 Kbps PT 6 3 Mbps 1 Mbps 682 Kbps 3 Mbps 341 Kbps CT 7 512 Kbps 256 Kbps 170 Kbps 512 Kbps 85 Kbps Page 12 of 12