Solved

External DNS settings for Mobile Clients on backup internet line

Posted on 2013-10-22
3
279 Views
Last Modified: 2013-10-28
I currently have mobile users who use software installed on their PCs that connects to our server using our external WAN IP and port forwarding.

The router connecting to the server has a backup internet line from a separate ISP.

Currently, if the internet goes down, I need to log into each mobile client and reconfigure the software to connect using the backup WAN IP.

I haven't had to do this yet, but don't want to in the future.

The software can use either a Hostname or IP.

If I configure the software to use a Hostname, is there a way to configure DNS to point to the primary WAN IP, but when it is down, switch to the backup WAN IP?

Or would I be stuck with setting it up with a short TTL and changing it manually when the connection is down.
0
Comment
Question by:pmitllc
  • 2
3 Comments
 
LVL 14

Accepted Solution

by:
Giovanni Heward earned 500 total points
Comment Utility
You'd want the mobile devices to point to a FQDN.  You'd then create two corresponding A records which resolve to the separate IP addresses.  Once the mobile device fails to connect to one A record IP address it should try the secondary IP address automatically.

If not, then you could use a very low TTL value and update the IP address manually for a single A record.  

You'd need to test the multiple A record approach with each unique mobile device (make/model) to see how it's TCP/IP stack responds when being presented with multiple A records, and when encountering a timeout condition with one of the IP addresses.

Unfortunately with the dual A record approach you don't necessarily have control over which A record is attempted first.  While it's possible whichever one is presented first is used, it may vary between mobile devices.  The device may perform a round robin approach between the two IP addresses.  Either way, the possible effect being your "backup" line is responding to requests when your "primary" line is operational.
0
 
LVL 6

Author Closing Comment

by:pmitllc
Comment Utility
I think I am going to use the low TTL method.  At least I will only have to change one thing if the internet goes down.
0
 
LVL 14

Expert Comment

by:Giovanni Heward
Comment Utility
That's probably preferable.  Another way to go would be to write a script which checks the primary connection every x interval and updates the A record automatically when a timeout is encountered.  It could notify you via email/sms of the failure, and restore the A record to the primary IP address when the connection is restored.

This would be running on a remote site of course.  NPing for example (part of the Nmap package), could be used to connect to a specific port over a specific protocol, etc., in instances where ICMP is blocked.

nping --tcp -p 80 www.example.com

Open in new window


If your DNS provider doesn't have an API to do this, there are plenty of other options to automate authenticating and updating the record.  See Curl, etc.  Python, PHP, Perl, etc. all have the capability to do this.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
Resolve DNS query failed errors for Exchange
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now