Hi all,

I have scoured the archives for this issue, and couldn't find anything
relevant. Please forgive me if I am bringing up something recent.

Topology:

ISP A                    ISP B
   |                            |
   |                            |
   |                            |
   |                            |
Router A            Router B
   |                            |
   |                            |
   |                            |
Firewall A         Firewall B
   |                            |
   |                            |
   |                            |
   |                            |
   -------Web server-------

The issue is this. An ISP is using 3DNS to handle DNS for a web server
that is multihomed to two separate ISP's. For those of you unfamiliar
with 3DNS, it is an intelligent DNS server that checks TCP connectivity
to a host before handing out an IP address. So for example, in this
situation the ISP is checking http connectivity to each network
interface of the web server. Because the web server only has one default
gateway (Firewall B), it is impossible to check connectivity to the NIC
on Network A because the reply goes to the Firewall B and is dropped as
an un-established TCP error (Stateful Firewalls).

I can't proxy, as the 3DNS server interprets the proxy server as being a
valid connection, even if the web server is down.

I am thinking of putting a Cisco router between firewall A and the web
server, that NAT's requests coming in from the 3DNS servers, and back
out to the 3DNS server.

Anyone had experience of this before?

Kind regards,

Symon Thurlow
Webvein Consulting Ltd

+44 (0)7799 064400
[EMAIL PROTECTED]
http://www.webvein.com




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=48166&t=48166
--------------------------------------------------
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to