How to Configure Link Balancing and Failover for Multiple WAN Connections

Similar documents
Barracuda Link Balancer

Enabling NAT and Routing in DGW v2.0 June 6, 2012

How To Configure Virtual Host with Load Balancing and Health Checking

Quick Note 53. Ethernet to W-WAN failover with logical Ethernet interface.

Smart Tips. Enabling WAN Load Balancing. Key Features. Network Diagram. Overview. Featured Products. WAN Failover. Enabling WAN Load Balancing Page 1

Using IPsec VPN to provide communication between offices

ASA/PIX: Load balancing between two ISP - options

Chapter 3 Security and Firewall Protection

Routing concepts in Cyberoam

Configuring a Mediatrix 500 / 600 Enterprise SIP Trunk SBC June 28, 2011

Using VDOMs to host two FortiOS instances on a single FortiGate unit

Configuring Switch Ports and VLAN Interfaces for the Cisco ASA 5505 Adaptive Security Appliance

Configuring Network Load Balancing with Cerberus FTP Server

Configuring the BIG-IP and Check Point VPN-1 /FireWall-1

Digi Connect WAN Application Helper Configuring and Testing the Digi Connect WAN GSM

Hosting more than one FortiOS instance on. VLANs. 1. Network topology

How do I configure multi-wan in Routing Table mode?

Optimum Business SIP Trunk Set-up Guide

Configuring WAN Failover & Load-Balancing

I. What is VPN? II. Types of VPN connection. There are two types of VPN connection:

IP Address and Pre-configuration Information

Chapter 2 Connecting the FVX538 to the Internet

Barracuda Link Balancer Administrator s Guide

How to Perform a Manual High Availability Failover

FAQs: MATRIX NAVAN CNX200. Q: How to configure port triggering?

Configuring IPsec VPN with a FortiGate and a Cisco ASA

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

Chapter 9 Monitoring System Performance

Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.

LAN TCP/IP and DHCP Setup

TotalCloud Phone System

How to Configure a High Availability Cluster in Azure via Web Portal and ASM

Chapter 8 Router and Network Management

Configuring the Edgewater 4550 for use with the Bluestone Hosted PBX

Appendix C Network Planning for Dual WAN Ports

Multifunctional Broadband Router User Guide. Copyright Statement

How to setup PPTP VPN connection with DI-804HV or DI-808HV using Windows PPTP client

Application Notes. How to Configure Application Control for the UTM

Configuring a FortiGate unit as an L2TP/IPsec server

Best Practices: Pass-Through w/bypass (Bridge Mode)

Basic IPv6 WAN and LAN Configuration

Network/VPN Overlap How-To with SonicOS 2.0 Enhanced Updated 9/26/03 SonicWALL,Inc.

Firewall Defaults and Some Basic Rules

Cisco - Configure the 1721 Router for VLANs Using a Switch Module (WIC-4ESW)

Connecting to the Internet. LAN Hardware Requirements. Computer Requirements. LAN Configuration Requirements

Port forwarding and viewing your IP camera from the internet

Configuring High Availability for Embedded NGX Gateways in SmartCenter

Chapter 8 Advanced Configuration

ICS 351: Today's plan. IP addresses Network Address Translation Dynamic Host Configuration Protocol Small Office / Home Office configuration

Configuring WAN Failover with a Cisco 881 Router and an AirLink ES440

1:1 NAT in ZeroShell. Requirements. Overview. Network Setup

How to configure VLAN and route failover

PPTP Server Access Through The

Quick Installation Guide

< Introduction > This technical note explains how to connect New SVR Series to DSL Modem or DSL Router. Samsung Techwin Co., Ltd.

UIP1868P User Interface Guide

vcloud Air - Virtual Private Cloud OnDemand Networking Guide

Integrating Citrix EasyCall Gateway with SwyxWare

Yealink VCS Network Deployment Solution

Internet Access Setup

How To Authenticate An Ssl Vpn With Libap On A Safeprocess On A Libp Server On A Fortigate On A Pc Or Ipad On A Ipad Or Ipa On A Macbook Or Ipod On A Network

Load Balance Mechanism

Chapter 4 Customizing Your Network Settings

Broadband Phone Gateway BPG510 Technical Users Guide

Prestige 202H Plus. Quick Start Guide. ISDN Internet Access Router. Version /2004

Enabling VPN on your VPS

VMware vcloud Air Networking Guide

How to configure your Thomson SpeedTouch 780WL for ADSL2+

NAT (Network Address Translation)

Digi Connect WAN Application Guide Using the Digi Connect WAN and Digi Connect VPN with a Wireless Router/Access Point

How To Load balance traffic of Mail server hosted in the Internal network and redirect traffic over preferred Interface

Chapter 12 Supporting Network Address Translation (NAT)

Fonality. Optimum Business Trunking and the Fonality Trixbox Pro IP PBX Standard Edition V p13 Configuration Guide

Appendix IP CAMERA Network Connections

Chapter 4 Customizing Your Network Settings

Elfiq Link Balancer (Link LB) Quick Web Configuration Guide

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

Chapter 3 LAN Configuration

PC/POLL SYSTEMS Version 7 Polling SPS2000 Cash Register TCP/IP Communications

THINKTEL COMMUNICATIONS TALKSWITCH VS TALKSWITCH VS THINKTEL SIP TRUNK & DID

Route Based Virtual Private Network

Configuring SSL VPN on the Cisco ISA500 Security Appliance

GlobalSCAPE DMZ Gateway, v1. User Guide

Balancing and Gateway Failover

Serial Deployment Quick Start Guide

Supporting Multiple Firewalled Subnets on SonicOS Enhanced

IP Office - Job Aid Remote Access

Scenario 1: One-pair VPN Trunk

Multi-Homing Dual WAN Firewall Router

WAN Failover Scenarios Using Digi Wireless WAN Routers

Configuration Notes 0217

Wireless G Broadband quick install

Wireless Local Area Networks (WLANs)

Configuring a customer owned router to function as a switch with Ultra TV

Firewall VPN Router. Quick Installation Guide M73-APO09-380

SETTING UP REMOTE ACCESS ON EYEMAX PC BASED DVR.

nexvortex Setup Template

Chapter 7. Address Translation

Transcription:

How to Configure Link Balancing and Failover for Multiple WAN Connections If you are using two DHCP connections from the same carrier that is using the same remote network and gateway, see How to Configure Automatic Failover with Dual DHCP WAN Connections using the Same Remote Gateway. If you are using two or more ISP connections, you can use outbound link and load balancing to balance the traffic between the different Internet connections. If one ISP goes down, the traffic will be routed over the remaining connection. Basic link failover functionality can be achieved by using different route metrics. A better solution is to use custom connection objects to distribute the load and/or configure failover for different links. Using custom connection objects allows you to decide on link balancing on a per-access rule basis. For this article, we assume we are using a mix of one static and one dynamic (DHCP) Internet connection. In this article: Step Configure the WAN Connections Configure your WAN connections: For information on setting up an ISP with static IP address assignment, see How to Configure an ISP with Static IP Addresses -D. For information on setting up an ISP with dynamic DHCP IP address assignment, see How to Configure an ISP with Dynamic IP Addresses (DHCP). This configuration uses the following example settings for both WAN connections: ISP IP Address Gateway Network Interface ISP 1 699.0.69 699.0.254 port 3 ISP 2 dynamically assigned dynamically assigned For WAN connections with dynamic address assignment (e.g.,dhcp), verify that you enable the settings Own dhcp How to Configure Link Balancing and Failover for Multiple WAN Connections 1 / 5

Routing Table, Use Assigned IP, Create Default Route, and Clone Routes in the configuration. Step Add a Source Based Route Configure the source routes for both connections to avoid IP packets from being sent via the wrong ISP line. For DHCP connections, the routes are already introduced automatically by the DHCP client. For ISP connections with static IP addresses, configure a source-based route. 9. 10. 1 1 1 1 Open the Network page (Config > Full Config > Box). In the left menu, select Routing. In the Source Based Routing section, click + to add a new route. Enter a Name for the route and click OK. In the Source Networks table, add the network for which the routing table is consulted., e.g., 699.0.0/24 In the Routing Table Contents section, click + to configure the route. In the Target Network Address field, enter 0.0.0.0/0. Select unicast as the Route Type. Enter the Gateway IP address, e.g., 699.0.254 Select postmain as the Table Placement option. Step Configure Link Monitoring For the dynamic Internet connection, configure link monitoring for both routes (default and source based) to monitor IP addresses beyond the ISP gateway. Open the Network page (Config > Full Config > Box). In the left menu, select xdsl/dhcp/isdn. In the Configuration Mode menu, select Switch to Advanced. Edit the DHCP link. In the Connection Monitoring section, add a target IP address to be used for monitoring into the Reachable IPs table. This address must be reachable only via the DHCP connection. After you configure your routes, you must activate your new network configurations. Go to the Control > Box page. In the left menu, expand Network and click Activate new network configuration. Select Failsafe. A Network Configuration Reconfigured message will appear. Step Create a Custom Connection Object for Link Balancing with Failover (Fallback) The Barracuda NG Firewall can perform link failover and link cycling using multiple connections. The failover and load balancing policy used in the custom connection object defines how the traffic is routed: How to Configure Link Balancing and Failover for Multiple WAN Connections 2 / 5

Link Balancing with Fallback Traffic is always routed over the primary uplink as long as it is available. If the main uplink fails, the secondary uplink is used. Random Link Balancing Sessions are distributed randomly according to the weight of the connections. If one of the connections fails, traffic is routed through the other available connections as defined in the connection policy. Sequential Link Balancing The Source IPs are sequentially cycled through, factoring in the weight defined for each uplink. The Barracuda NG Firewall remembers the sources/destination of active sessions and will reuse the same connection if a similar connection is established. Create a custom connection object for link balancing and failover: Open the Forwarding Rules page (Config > Full Config > Virtual Servers > your virtual server > Assigned Services > Firewall). In the left menu, click on Connections. Right-click and select New. The Edit/Create a Connection Object window opens. Enter a Name for the connection object. E.g., LBFailover Select From Interface as the NAT Address. 9. 10. In the Interface Name field, enter the port the ISP 1 is connected to. E.g.,port3 or dhcp In the Failover and Load Balancing section, select one load balancing/failover Policy: FALLBACK (Fallback to alternative Source Addresses) Select either Interface or source IP address for each Internet connection. Enter the interface or source IP address for the connection. SEQ (Sequentially cycle Source Addresses) Select either Interface or source IP address for each Alternative connection. Enter the interface or source IP address for each connection. Enter the Weight factor. This value determines how the load is distributed between the different connections. RAND (Random Source Addresses) Select either Interface or source IP address for each Alternative connection. Enter the interface or source IP address for each connection. Enter the Weight factor. This value determines how the load is distributed between the different connections. Step Apply the Connection Object Use the object for all access rules handling outgoing traffic. Open the Forwarding Rules page (Config > Full Config > Virtual Servers > your virtual server > Assigned Services > Firewall). Edit an access rule handling outgoing traffic. E.g., LAN-2-INTERNET Select the custom connection object created in Step 4 from the Connection Method list. How to Configure Link Balancing and Failover for Multiple WAN Connections 3 / 5

Step (optional) Configure Notifications You can configure the Barracuda NG Firewall to send SNMP traps or email notifications in case one of the ISP connections fails. Depending on what kind of notification you want to send, change the notification ID for: 62 (Route Changed) 64 (Route Disabled) For more information, see Events. You are now load balancing and/or using failover for all outgoing connections, which are handled by access rules using the custom connection object. If needed, you can define multiple custom connection objects and use them to control which ISP connections are used by a specific network or IP address. How to Configure Link Balancing and Failover for Multiple WAN Connections 4 / 5

How to Configure Link Balancing and Failover for Multiple WAN Connections 5 / 5