Solved

Cisco IP SLA Firewall Equivilant

Posted on 2013-10-29
2
816 Views
Last Modified: 2013-10-29
On common problem that you have to deal with in a network is choosing the best path.  In small companies often this just means keeping a group of say 20, 40 people connected
to the Internet.  With Cisco IOS there is a feature I really like called "IP SLA" where I can set a target IP address and use ICMP Echo to verify that the path is good and then setup routes that rely on this upnessness.  If the path goes bad a floating static route with a higher weight is ready to take over in just a few seconds.  It works flawlessly.  

I wondered if a similar feature existed in either Cisco or other firewalls (Sonicwall, Juniper, other?).  And I have one additional requirement.  

                                                {ISP A}
So imagine (LAN)---[Firewall]<
                                                {ISP B}

Hopefully that beautiful ASCII art draws ok when I post.  But in effect I want two ISPs
on the outside of my firewall.  Each ISP has given me a small /27 block.  I want the firewall to verify the path to the Internet is good via each ISP and for it to prefer ISP A in most cases.  What firewalls have the equivalent of IP SLA to assure that there is a good path to the Internet at all times?  I assume I would have two Outside Interfaces and one inside interface and NAT would correspond with the path taken.
0
Comment
Question by:amigan_99
2 Comments
 
LVL 25

Accepted Solution

by:
Diverse IT earned 500 total points
ID: 39609570
Hi amigan_99,

In every SonicWALL Security Appliance currently available this is just called multi-WAN failover/load-balancing (LB). For failover you can use a few different schemes: Basic Active/Passive Failover, Round Robin, Spillover-Based, or Percentage-Based (Ratio). It then probes the IPs and deactivates/reactivates based on the responses and your configuration.

I know you can us LB for other zones but not sure if fail-over is available for other zones outside of the WANs.

Let me know if you have any other questions!
0
 
LVL 1

Author Closing Comment

by:amigan_99
ID: 39609676
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now