Solved

Sonicwall WAN loadbalancing issues?

Posted on 2010-11-22
4
940 Views
Last Modified: 2012-05-10
Hi Experts,

I have a Sonicwall 2040 configured with WAN failover. I have 2 ISP for 2 internet connections.

ISP1: 206.45.x.24/29 ---> X1 interface.
ISP2: 73.12.x.52/29   ---> X2 interface.

On local network (X0 interface), I also have exchange and web server which go to the public internet. The rules are being set for X1 interface. What do I have to do to make sure when it failover to X2 interface, all the exchange and web servers still can visible to the public?

Thanks.
0
Comment
Question by:SJCA
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:cgaeden
ID: 34192214
I believe that you'll need to have external DNS for your mail and web servers setup on the Internet with a low TTL (time to live) for each of their entries. If or when your primary ISP fails, you'll need to have entries setup on your Sonicwall using your alternate ISP's IP addresses that point to your internal servers. Should a failover occur, you would then update the DNS entries for those servers with the alternate ISPs IPs and after the TTL expires traffic will flow to the alternate addresses for those servers.

You could potentially update the IP addresses dynamically using a service like dyndns.org or dnsmadeeasy.com and running a Dynamic DNS client on your servers.

Are you using NAT to pass traffic through to your servers now?
0
 
LVL 1

Author Comment

by:SJCA
ID: 34192241
Yes, I'm using NAT to pass traffic.
0
 
LVL 1

Author Comment

by:SJCA
ID: 34192411
IS there anyway that I don't have to update my dns entries? I just want the email and web server keep working without having any issue after the failover second ISP.
0
 
LVL 3

Accepted Solution

by:
cgaeden earned 500 total points
ID: 34192672
You can use BGP to have a consistent set of publicly routable IP addresses across both ISPs, but appart from that, none that I know of.

The dyn-dns option isn't too bad if you can live with a potential 5 minute interruption in services. It really depends on what your set the TTL at on the DNS server. You can always drop your TTL down for individual servers, but know that you'll increase the number of hits on your DNS server if you do. As the TTL expires, people trying to contact your email or web servers will generate another DNS query for those services.
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question