|
If this will be a cluster configuration -- that is, allowing session failover,
and if necessary, vpn-failover, then the two boxes will be defined as a
cluster, therefore each internal subnet must be hidden behind one ip.
If you decide to break the state synchronization by configuring the two
boxes as totally separate entities, and allowing yourself to enforce different
hide addresses for the same subnet on two boxes, you will run into problems
with dynamically generated web pages when failover occurs, because the
source address for a session will change and the remote server will be
unable to swap the remote association.
Don't get me wrong, Rainfinity is a great product, but to do this solution flawlessly, you should still listen to the first response "Mark L. Decker" wrote: Actually, there is a way to do this (at least for outbound access and mail) without BGP, but it requires two firewalls in a RainWall cluster. You connect one firewall to ISP A and the other firewall to ISP B, and both to the same internal subnet. The firewall A does NAT using range from ISP A, and firewall B does NAT using range from ISP B. Then you set up the RainWall Ping Monitor to watch the ISP links. If link to ISP A goes down, RainWall can automatically disable firewall A, and move its internal IP address to firewall B, thereby redirecting users out to ISP B. This also allows load sharing of outbound traffic between the two links. It does not help in the case of inbound access to an internally hosted webserver, but mail will still work if you use multiple MX records. Failover is automatic, but not transparent (because src/dest pair changes). Not a perfect solution, but then neither is BGP.Mark L. DeckerRainfinity[EMAIL PROTECTED](408) 382-4870 |
- [FW1] Multiple WAN Links. Gunjan Mathur at 9netave
- Re: [FW1] Multiple WAN Links. CryptoTech
- RE: [FW1] Multiple WAN Links. Mark L. Decker
- RE: [FW1] Multiple WAN Links. CryptoTech
- RE: [FW1] Multiple WAN Links. Mark L. Decker
- RE: [FW1] Multiple WAN Links. Scopelliti, Pasquale F
- RE: [FW1] Multiple WAN Links. Mark L. Decker
- RE: [FW1] Multiple WAN Links. iden fw
- RE: [FW1] Multiple WAN Links. Mark L. Decker
- RE: [FW1] Multiple WAN Links. iden fw
- RE: [FW1] Multiple WAN Links. Mark L. Decker
- RE: [FW1] Multiple WAN Links. Ed Davidson
- RE: [FW1] Multiple WAN Links. Lee Hughes
- [FW1] RE: Multiple ISPs Mark L. Decker
