Solved

Adding Redundancy with MPLS and Sonic Firewall

Posted on 2011-02-23
4
871 Views
Last Modified: 2013-11-16
I'm searching their db to see if there are any other solutions resembling the issue I'm trying to get a solution for. Below you will notice the setup; not the most ideal solution; but in a nutshell

The CISCO routers are managed by the carrier additionally the carrier has the Cisco devices programmed so that if MPLS link goes down on the WAN side route all traffic back to the LAN side of the Cisco which will forward all traffic to the X0 interface IP of the Sonicwall. The Sonicwall has VPN tunnels configured from remote to HQ site in this case let's say HQ is 10.0.13.0  

The default gateway for all clients in a node will be the Cisco (CE) device. problem is that when we test failover to the Sonicwall the Cisco sends traffic to the Sonicwall; but the Sonicwall will not receive a response back from the remote Sonicwall I believe the end node may be trying to route the information via the MPLS network at HQ since all clients are programmed for the CISCO to be the default gateway. If I set all clients to route traffic to the Sonicwall as a default would I be able to configure 2 redundant routes and if link is down failover to the VPN tunnel as secondary?
 

 MPLS Config
0
Comment
Question by:GridLock137
  • 2
  • 2
4 Comments
 
LVL 33

Expert Comment

by:digitap
ID: 34964955
alot of times it would depend on how the connection goes down.  i would assume if the mpls goes down and both sides are using the cisco as the default route, then this "down" condition would be coordinated.  so, each cisco would route their traffic to the sonicwalls.  the sonicwalls would have their VPNs up and traffic would route.  it's supposed to happen this way or at least how you expect it to happen?

there is a way to setup to gateways and configure a route to be disabled if the interface goes offline.  however, in this case, you might have some challenges if the cisco router stays online but the mpls "down" issue is beyond the cisco router and the sonicwall can't detect that.
0
 
LVL 7

Accepted Solution

by:
GridLock137 earned 0 total points
ID: 34965034
Found this to be the solution for the current topology  http://www.fuzeqna.com/sonicwallkb/consumer/kbdetail.asp?kbid=8445

would this work?
0
 
LVL 33

Expert Comment

by:digitap
ID: 34965087
that's describing your situation exactly.  it's what i would have recommended.  i've not come across this configuration before.
0
 
LVL 7

Author Closing Comment

by:GridLock137
ID: 34995513
quick one I guess
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Routing between two networks? 10 52
VirtualBOX on GNS3 11 115
Need to separate small office by VLAN... 3 68
Two IPV6 prefixes have same meaning under prefix-set in ASR9K? 2 22
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question