Balancing and Gateway Failover



Similar documents
How To Load balance traffic of Mail server hosted in the Internal network and redirect traffic over preferred Interface

How To Configure Virtual Host with Load Balancing and Health Checking

How To - Configure Virtual Host using FQDN How To Configure Virtual Host using FQDN

How To - Deploy Cyberoam in Gateway Mode

This article describes a detailed configuration example that demonstrates how to configure Cyberoam to provide the access of internal resources.

Cyberoam Multi link Implementation Guide Version 9

How To Configure Syslog over VPN

How To Configure SSL VPN in Cyberoam

DSL-G604T Install Guides

How To Configure L2TP VPN Connection for MAC OS X client

ASUS WL-5XX Series Wireless Router Internet Configuration. User s Guide

Chapter 5 Customizing Your Network Settings

Steps for Basic Configuration

Unified Threat Management

How To Establish IPSec VPN connection between Cyberoam and Mikrotik router

How To Establish IPSec VPN between Cyberoam and Microsoft Azure

Routing concepts in Cyberoam

Best Practices: Pass-Through w/bypass (Bridge Mode)

Configuring WAN Failover & Load-Balancing

How To - Implement Clientless Single Sign On Authentication in Single Active Directory Domain Controller Environment

N300 WiFi Range Extender WN2000RPT User Manual

Chapter 2 Connecting the FVX538 to the Internet

Configuring High Availability for Embedded NGX Gateways in SmartCenter

How To Establish Site-to-Site VPN Connection. using Preshared Key. Applicable Version: onwards. Overview. Scenario. Site A Configuration

Deployment Guide: Transparent Mode

2.0 Dual WAN Select Dual-WAN, you will see the following screen shot, Figure 0.1(Dual-WAN Screen Shot) Figure 0.1(Dual-WAN Screen Shot)

Chapter 1 Configuring Basic Connectivity

Cisco - Configure the 1721 Router for VLANs Using a Switch Module (WIC-4ESW)

Total Business Continuity with Cyberoam High Availability

Wireless Router Quick Start Guide Rev. 1.0a Model: WR300NQ

Cyberoam Virtual Security Appliance - Installation Guide for VMware ESX/ESXi. Version 10

Quick Start Guide for Zone Director Controller

ZyWALL USG-Series. How to setup a Site-to-site VPN connection between two ZyWALL USG series.

P-791R v2. Quick Start Guide. G.SHDSL.bis Router DEFAULT LOGIN. Administrator Password User Password. Version /2007 Edition 1

NAS 307 Link Aggregation

RF550VPN and RF560VPN

Deploying Windows Streaming Media Servers NLB Cluster and metasan

DFL-210/260, DFL-800/860, DFL-1600/2500 How to setup IPSec VPN connection

F-Secure Messaging Security Gateway. Deployment Guide

Setting up VPN connection: DI-824VUP+ with Windows PPTP client

ZTE Australia Help Guides MF91

Internet Access to a DVR365

How to configure WFS (Windows File Sharing ) Acceleration on SonicWALL WAN Acceleration Appliances

Cyberoam Virtual Security Appliance - Installation Guide for XenServer. Version 10

Chapter 1 Installing the Gateway

Using SonicWALL NetExtender to Access FTP Servers

Configuring a BEC 7800TN Wireless ADSL Modem

Multi-Homing Security Gateway

SonicWALL Global Management System Configuration Guide Standard Edition

Configuring Trend Micro Content Security

Lab Configuring Access Policies and DMZ Settings

VPN Configuration of ProSafe Client and Netgear ProSafe Router:

Deploying Silver Peak VXOA Physical And Virtual Appliances with Dell EqualLogic Isolated iscsi SANs including Dell 3-2-1

Internet Redundancy How To. Version 8.0.0

MN-700 Base Station Configuration Guide

Chapter 1 Configuring Internet Connectivity

Chapter 8 Advanced Configuration

Chapter 4 Customizing Your Network Settings

Configure VPN between ProSafe VPN Client Software and FVG318

LinkProof DNS Quick Start Guide

Chapter 10 Troubleshooting

Deploying Virtual Cyberoam Appliance in the Amazon Cloud Version 10

Creating a Gateway to Client VPN between Sidewinder G2 and a Mac OS X Client

Configuring a customer owned router to function as a switch with Ultra TV

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

Chapter 4 Customizing Your Network Settings

How to Create a Virtual Switch in VMware ESXi

DRO-210i LOAD BALANCING ROUTER. Review Package Contents

CommandCenter Secure Gateway

MULTI WAN TECHNICAL OVERVIEW

Networking Guide Redwood Manager 3.0 August 2013

Talk2M Free+ Remote-Access Connectivity Solution for ewon COSY devices. Getting Started Guide

Establishing a VPN tunnel to CNet CWR-854 VPN router using WinXP IPSec client

StarWind iscsi SAN Software: Using StarWind with MS Cluster on Windows Server 2003

SOHO 6 Wireless Installation Procedure Windows 95/98/ME with Internet Explorer 5.x & 6.0

How do I configure multi-wan in Routing Table mode?

CyberGuard SG Firewall VPN Appliance. User Manual

StorSimple Appliance Quick Start Guide

How To Set Up A Computer With A Network Connection On A Cdrom 2.5 (For A Pc) Or Ipad (For Mac) On A Pc Or Mac Or Ipa (For Pc) On An Ipad Or Ipro (

Customer Installation Guide NBG-4615 v2 ZyXEL Wireless Router

1:1 NAT in ZeroShell. Requirements. Overview. Network Setup

IPsec VPN Application Guide REV:

Supporting Multiple Firewalled Subnets on SonicOS Enhanced

801.11n Wireless Broadband Router

Firewall Defaults and Some Basic Rules

Network Load Balancing

Setting up D-Link VPN Client to VPN Routers

How To - Implement Single Sign On Authentication with Active Directory

Configuring Windows Server Clusters

BROADBAND INTERNET ROUTER USER S MANUAL. Version Page 1 of 13 -

Step by step guide for installing highly available System Centre 2012 Virtual Machine Manager Management server:

Connecting the DG-102S VoIP Gateway to your network

Check Your Package Contents. CD-ROM containing Manual and Warranty

NBG2105. User s Guide. Quick Start Guide. Wireless Mini Travel Router. Default Login Details. Version 1.00 Edition 1, 11/2012

Multifunctional Broadband Router User Guide. Copyright Statement

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

Configuring SSL VPN on the Cisco ISA500 Security Appliance

IP-6600 Router Configuration Quickstart Backing Up a Broadband Connection with Dialup

DSL-2500U. D-Link. User Manual. ADSL2/2+ Ethernet Router. RECYCLABLE 2006/08/30 Ver Building Networks for People

Transcription:

How To Add Active How or To Backup Add Gateway Active for Load or Backup Balancing and Gateway for Failover Load Balancing and Gateway Failover Applicable versions: 9.5.3 build 18 onwards Today organizations require stable, redundant and fast ISP links to run business critical applications. To achieve constant and secure availability to the Internet and to avoid network vulnerability, organizations prefer to have multiple ISP links. Multiple ISP links provisions network administrator to configure failover and load balancing over Internet links. Cyberoam supports load balancing and failover for multiple ISP links based on number of WAN ports available in the Appliance This document explains procedure to add secondary ISP link and configure load balancing and gateway failover with the following sections: Add a New Gateway Load Balancing and Failover (Active-Active) Configure Backup Gateway (Active-Backup) Configure Gateway Failover Network scenario: Consider the hypothetical network in which one ISP link is terminated on Port B and Administrator wants to terminate another ISP link on Port D.

Below given IP schema is configured on Cyberoam. Parameters Value Port A IP Address 10.10.1.1 Subnet Mask 255.255.255.0 LAN Port B IP Address 172.16.16.1 Subnet Mask 255.255.240.0 WAN Gateway Details ISP Name Default IP Address 172.16.16.15 Port C IP Address 10.10.10.1 Subnet Mask 255.255.255.0 DMZ Port D Port D is an unbound port so zone type for port D is set to None DNS Configuration Primary DNS 66.28.0.61 Add a New Gateway Pre-requisite An unbound physical port should be available on Cyberoam. An unbound port is one, which is not assigned to any security zone. Following are the steps to add a new Gateway: 1. Log on to Web admin console 2. Click to run the Network Configuration Wizard. 3. Under and Network Configuration section, using Next button go to port D and configure following values: Select Use Static IP IP Address: 10.10.2.1 Subnet Mask: 255.255.255.0 : WAN Gateway Details ISP Name: Cyberoam_1 IP Address: 10.10.2.19 4. Click Next to proceed 5. Click to proceed further and click Finish to complete network configuration

It will take few minutes to save the configuration details. Cyberoam will take some time to restart, wait for sometime before clicking the URL to access the Web Admin console. 6. If the gateway is added successfully, it will be enabled automatically and its status would be Active and weight as 1.You can confirm the gateway status from Web Admin console, System Gateway Manage Gateway(s) page Load Balancing and Failover (Active-Active) As the newly added gateway Cyberoam_1 is operating as Active gateway, Cyberoam will automatically distribute the traffic between both the links. Cyberoam employs weighted round robin algorithm for load balancing to enable maximum utilization of capacities across the various links. To achieve failover for the Active-Active gateways, one has to define the failover condition for each gateway. In the considered example, if the Default gateway goes down and failover condition is defined then the entire traffic will be processed by the Cyberoam_1 gateway and vice versa. Please refer Configure Failover Condition section to define fail over rules for the active gateway.

Configure Backup Gateway (Active-Backup) A gateway can be configured to operate as a Backup gateway. Backup gateway comes up when any of active gateways goes down. Hence, load balancing will not be done in case of active- back up scenario. To configure backup gateway 1. Go to System Gateway Manage Gateways 2. Click Gateway Name to be configured as back up gateway 3. Under Gateway Details section change Gateway Type to Backup 4. Configure Backup Gateway Details as per below image Initially traffic will not pass through the backup gateway. When any of active gateways fails then only traffic will be routed to backup gateway with inherited weight of failed active gateway Configure Failover Condition 1. Log on to Web admin console 2. Go to System Gateway Manage Gateways 3. Click Gateway Name to configure failover condition. By default, Cyberoam creates Ping rule for every gateway. Cyberoam periodically sends the ping request to check health of the link and if link does not respond, traffic is automatically sent through another available link. Click checkbox to enable default failover rule. 4. Click Add to add multiple failover conditions in the failover rule 5. Configure failover rule as per below image:

Configure host must be represented by the computer or Network device which is permanently running or most reliable. 6. Click Save to save failover rule and gateway configuration In below screen shot active gateway has been failed and entire traffic is routed through back up gateway Cyberoam_1 During a link failure, Cyberoam regularly checks the health of a given connection, assuring fast reconnection when Internet service is restored. When the connection is restored and gateway is up again, without the administrator s intervention, traffic is again routed through the Active gateway. In other words, backup gateway fails back on Active gateway. Document version:1.0-21/07/2009