Solved

Sonicwall WAN loadbalancing issues?

Posted on 2010-11-22
4
935 Views
Last Modified: 2012-05-10
Hi Experts,

I have a Sonicwall 2040 configured with WAN failover. I have 2 ISP for 2 internet connections.

ISP1: 206.45.x.24/29 ---> X1 interface.
ISP2: 73.12.x.52/29   ---> X2 interface.

On local network (X0 interface), I also have exchange and web server which go to the public internet. The rules are being set for X1 interface. What do I have to do to make sure when it failover to X2 interface, all the exchange and web servers still can visible to the public?

Thanks.
0
Comment
Question by:SJCA
  • 2
  • 2
4 Comments
 
LVL 3

Expert Comment

by:cgaeden
ID: 34192214
I believe that you'll need to have external DNS for your mail and web servers setup on the Internet with a low TTL (time to live) for each of their entries. If or when your primary ISP fails, you'll need to have entries setup on your Sonicwall using your alternate ISP's IP addresses that point to your internal servers. Should a failover occur, you would then update the DNS entries for those servers with the alternate ISPs IPs and after the TTL expires traffic will flow to the alternate addresses for those servers.

You could potentially update the IP addresses dynamically using a service like dyndns.org or dnsmadeeasy.com and running a Dynamic DNS client on your servers.

Are you using NAT to pass traffic through to your servers now?
0
 
LVL 1

Author Comment

by:SJCA
ID: 34192241
Yes, I'm using NAT to pass traffic.
0
 
LVL 1

Author Comment

by:SJCA
ID: 34192411
IS there anyway that I don't have to update my dns entries? I just want the email and web server keep working without having any issue after the failover second ISP.
0
 
LVL 3

Accepted Solution

by:
cgaeden earned 500 total points
ID: 34192672
You can use BGP to have a consistent set of publicly routable IP addresses across both ISPs, but appart from that, none that I know of.

The dyn-dns option isn't too bad if you can live with a potential 5 minute interruption in services. It really depends on what your set the TTL at on the DNS server. You can always drop your TTL down for individual servers, but know that you'll increase the number of hits on your DNS server if you do. As the TTL expires, people trying to contact your email or web servers will generate another DNS query for those services.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This subject  of securing wireless devices conjures up visions of your PC or mobile phone connecting to the Internet through some hotspot at Starbucks. But it is so much more than that. Let’s look at the facts: devices#sthash.eoFY7dic.
The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
This is a video describing the growing solar energy use in Utah. This is a topic that greatly interests me and so I decided to produce a video about it.
Need to grow your business through quality cloud solutions? With everything required to build a cloud platform and solution, you may feel like the distance between you and the cloud is quite long. Help is here. Spend some time learning about the Con…

947 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now