VPN device with dual ISP, fail-over, and load balancing
We currently service a client that has a PIX firewall that connects to multiple, separate outside vendors via IPSEC VPN. The VPN connections are mission critical and if for any reason the VPN device or the internet connection (currently only a T1) goes down, the business goes down too. We're looking for a solution that allows dual-ISP, failover, and load balancing. I see that there are several ASA models as well as the IOS that support this but what I'm confused about is what are the requirements for the other end of the VPN, keeping in mind that the other end will always be an outside vendor and out of our control. Current VPN endpoints for outside vendors are to devices like VPN 3000 Concentrator, Sonicwall, etc. that likely do not support any type of fail-over, trunking, load-balancing. Is this just not possible?
Unless I am mistaken the ASA doesn't do VPN Load Balancing for point-to-point IPSec connections either. What you're really after is opportunistic connection failover, and/or something like DMVPN. Coordinating opportunistic failover shouldn't be too much of an issue with the partners, but be prepared for lot of questions.
Similar Messages
-
Web Dispatcher - Reverse Proxy and Load Balancing
I'm finding limited docs on Web Dispatcher with regard to reverse proxy and load balancing. Are you aware of some recent presentations or docs in this area? The info on help.sap.com is not what I'm looking for.
Thanks.Hi,
best thing is that you look at your scenarios and test the web dispatcher against each of it, like:
- SSL
- Portal only
- Web Dynpro ABAP / Java
- BSP
- Different backend systems like SRM, MDM
- Several backends with 1 Web Dispatcher
After getting a list of use cases that you can test quite easily (installation of Web Dispatcher is done fast and can be done on a local PC), you can contact SAP Support and ask them about the specific problems and questions you encountered. This way, you'll get the official answer, sometimes they will even inform you about "secret" parameters and options.
As of the reverse proxy functionality: there are several version of Web Dispatcher available that differ from the functionality offered. The latest version - 7.2 - is the one that offers the most, i.e. allows you to create rewrite rules like Apache.
SAP Note 908097 - SAP Web Dispatcher: Released releases and applying patches
br,
Tobias -
Performance Routing (PfR) with single router, dual ISP and load balancing
It looks like PfR can do this but I have only found information about this feature which will start using ISP2 once ISP1 reaches 75% usage. But this is not load balancing.
Can we accomplish load balancing utilizing a single router with dual ISPs using this PfR feature?
Or do we have to use another feature?
thank you in advanceDisclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
I'm rusty using OER/PfR, but I recall it could load balance two links on same router. The issue, I also recall, if doing BGP, OER/PfR has to detect a load imbalance, and there's a certain difference allowance, and OER/PfR takes some time to decide, so depending on actual traffic, it might not be obvious it's working. If doing BGP, there's a hidden command (which I don't recall is) that will load balance the two links on the same router; then you use OER/PfR to dynamically refine the balance load. -
Time Machine Failing Over and Over
So I am backing up my EX HD with Time Machine for the first time and it keep failing. It stops between 3 gb and about 20gb (I have 180 total). Keeps giving the error "The backup was not performed because an error occurred while copying files to the backup disk ". The HD I was using is a brand new Western Digital that I formatted two partitions. One for my old windows machine and this MBP. I formatted it exactly several times and it keeps failing.
My neighbor said I need to have a HD that is completely clean, so i went and bought a brand new Iomega HD just for Mac. It also failed over and over! I have read about every thread out there and cant seem to find a possible cause other than my internal HD is toast.
Has anyone else had this experience before?
-TSorry I'm not sure I understand your question now.
Let me try: if you excluded your Documents folder and TM now works, your backup size was likely the problem.
So if you simply remove Documents from the TM exclusion list you will run back into the size problem... no good.
If you first delete the large contents from the documents folder on your startup disk, then you can ask TM to backup again the Documents folder by removing it from the TM exclusion list, but obviously only what remains there (not the deleted material) will be saved by TM.
In other words, if you want to keep your 80 GB files on your startup disk, either you do not backup them or you use a larger backup disk. Otherwise you may remove the 80 GB from your startup disk; but now you probably want to keep 2 copies of them in 2 different external disks, for safety reasons, without using TM.
Did I answer your question ?
Piero
Message was edited by: PieroF -
If I can buy a new labtop with dual language keyboard English and Arabic
If I can buy a new labtop with dual keyboard language
English and ArabicKeyboards with Arabic on them always have English as well -- otherwise you would not be able to type email and webpage addresses.
As far as where you can buy something, you have to contact stores directly yourself, nobody here can do that for you. -
I do the same that is instructed in "If you have never synced your device with iTunes ".Everything works fine and itunes start restoring it and updating my ipad.But after 5 mints , same error again appears on itune screen.And also ipad goes into same disabled postion.What should i do ? Somebody help please.
See Here > http://support.apple.com/kb/HT1808
You may need to try this More than Once...
Some users have reported as many as 8 or 9 attempts were necessary before success.
Be sure to Follow ALL the Steps...
But... if the Device has been Modified... this will Not necessarily work. -
I have stored everything on my Macbook pro in a external hard drive (Time Machine) Now that we have "wiped the machine" I am told I can start it over and load ontent--apps, docs, etc from the hard drive, just plug it in, find the time machine and what? I need to know what to highligh, what to click on.
hirogliffix,
take a look at this Apple page — in particular, the “Restoring data from Time Machine backups” section and its “Restoring your entire system from a backup” subsection. -
Cache and Load Balancing with Oracle APEX Listener
Hi,
I intend to use only HTTP access.
How to implement a Cache and Load Balancing with the Oracle APEX Listener?
Is it possible to do with the the standalone running APEX Listener?
Thanks by advance for any tips/documentation/references.
Kind Regards.Hi,
I think this question is best asked in the APEX Listener forum:
ORDS, SODA & JSON in the Database
Kind regards
Sandro -
Data Centre Interconnection - firewall and load balancer deployment
Hi all,
I've read lots of Cisco docs/white papers on DCI - Layer 2 extension between DCs, but as yet I cannot find any decent information on how best to deploy firewalls and load balancers in such a design. I've seen refs to FHRP isolation on Nexus 7k (and possible 6k if you use DCI block) but nothing on the services elements.
The services element seems to be a complete minefield here:
- active/standby across sites, or deploy resilient pairs in each site?
- how to align optimal traffic flows inbound and ooutbound (RHI, SNAT, etc.)
- best practice suggestions ideally.
Cisco DCI docs seem to always gloss over the fact that most customers would have to deal with firewalls and load balancers here, and simply refer to 'coming soon' for that info.
If anyone has any good suggestions/links to docs explaining detailed implementation info would be much appreciate
Thanks
PhilYou might want to check out this new product called ITD.
Simple and faster solution:
ITD provides :
ASIC based multi-terabit/s L3/L4 load-balancing at line-rate
No service module or external L3/L4 load-balancer needed. Every N7k port can be used as load-balancer.
Redirect line-rate traffic to any devices, for example web cache engines, Web Accelerator Engines (WAE), video-caches, etc.
Capability to create clusters of devices, for example, Firewalls, Intrusion Prevention System (IPS), or Web Application Firewall (WAF), Hadoop cluster
IP-stickiness
Resilient (like resilient ECMP)
VIP based L4 load-balancing
NAT (available for EFT/PoC). Allows non-DSR deployments.
Weighted load-balancing
Load-balances to large number of devices/servers
ACL along with redirection and load balancing simultaneously.
Bi-directional flow-coherency. Traffic from A-->B and B-->A goes to same node.
Order of magnitude OPEX savings : reduction in configuration, and ease of deployment
Order of magnitude CAPEX savings : Wiring, Power, Rackspace and Cost savings
The servers/appliances don’t have to be directly connected to N7k
Monitoring the health of servers/appliances.
N + M redundancy.
Automatic failure handling of servers/appliances.
VRF support, vPC support, VDC support
Supported on both Nexus 7000 and Nexus 7700 series.
Supports both IPv4 and IPv6
N5k / N6k support : coming soon
Blog
At a glance
ITD config guide
Email Query or feedback:[email protected] -
Reverse Proxy and Load Balancer for SMP 2.3 and Agentry Application
Hi Expert,
I'm putting in place a mobile solution composed by SMP 2.3 SPS 4 and SAP ECC 6.0. In the SMP 2.3 I created the agentry server and I have deployed my agentry application.
My SMP/Agentry infrastructure is composed by two servers therefore I need a load balancer for balance the load into the several servers. Furthermore I need to use a reverse proxy in my DMZ zone.
Based on what indicated in the SAP note "1904213 - SAP Mobile Platform Server Release Information" the Apache Reverse Proxy is not supported for Agentry clients. Agentry uses nginx for Reverse Proxy.
I also found the following document How-to-Guide for Reverse Proxy and Load Balancing in SAP Mobile Platform 3.x that explain how to set-up a reverse proxy and load balancer with nginx and apache.
Both the SAP note and the HOW to document are refereed to SMP 3.0 and not to SMP 2.3.
I would know if the NGINX must be used also for SMP 2.3.
Any suggestion/information is appreciated.
Thanks in advance
g.Please see Agentry Network Landscapes
-
Cache and Load Balancing for the Oracle APEX Listener
Hi,
I intend to use only HTTP access.
My database is Oracle 11gR2, SE, 32 bit.
How to implement a Cache and Load Balancing with the Oracle APEX Listener?
Is it possible to do with the the standalone running APEX Listener?
Thanks by advance for any tips/documentation/references.
Kind Regards.Error. To be closed.
-
Cache and Load Balancing for Oracle APEX Listener
Hi,
I intend to use only HTTP access.
The database I use is Oracle11gR2 SE 32bit.
How to implement a Cache and Load Balancing with the Oracle APEX Listener?
Is it possible to do with the the standalone running APEX Listener?
Thanks by advance for any tips/documentation/references.
Kind Regards.Error. To be closed.
-
PIX Redundant Internet Line and Load balancing
I would like to find out if it's possible to configure my Cisco PIX 525 to use a secondary internet line from a different provider and perform load balancing. I'm using PIX Version 6.3(1)
PIX version 6.3 does not support Redundancy and load balancing. but PIX/ ASA with version 7.0 supports Redundancy.
-
What does per Wlan Band select and load balancing do ?
Good morning.....We recently upgraded our controllers from 4.2.185 to 6.0.188 and have noticed many clients having connectivity issues. We have Aggressive load balancing turned off globally but have noticed that band select and load balancing are enabled on the
Wlan. Are these settings mutually exclusive or do they do the same thing ? Does the Wlan setting override the default ? We have noticed that there is
output doing "debug dot11 load-balancing"
Thanx.....DaveI believe we never had load balancing turned on when running 5.2 code. We jumped from 5.2 to 6.x temporarily and then to 7.0 within a 30 day time frame this summer. We're a large university and we had very few users on WiFi during that time.
The Macintosh laptops are having nothing but trouble since school began, and I have gone over everything and found that band select is turned on as well as load balancing. Since band select didn't exist in 5.2 (I believe) I know it wasn't on. As for load balancing, I don't believe it was on, and I discovered it was turned on when recently reviewing our configs.
The Macintosh laptops have been debugged and our Mac gurus tell us they're getting a message that equates to "the AP is busy, or the AP is full". This leads me to believe that load balancing got turned on during the upgrade and we didn't notice, which caused the Macintoshes to have issues.
We don't have any VoWiFi clients so we don't have to support them, and we don't officially support smartphones, either.
I turned off load balancing and will see how it goes....
Thanks! -
ARFC: Single Server and Load Balancing
Hi All,
I am trying to create aRFC model. In SAP logon screen, I can see two tab pages - Single Server and Load Balancing.
Can you please let me know when we have to use which tab?
Thanks
TGSingle Server Connect or Load Balancing connect is completely independend from the location where SAP Gui Client is installed.
Single Server connect means that your are directly connecting to an ABAP Server using hostname and systemnumber you have to provide.
Load Balancing Connect means that you specify the message server of the central instance of an ABAP Server group. The SAPGUI first connects to the message server which will provide the SAPGUI with the information about the best performing ABAP server. SAPGUI will then connect to this ABAP server.
Single Server is suitable for small landscapes with lets say less than 4 application servers. In huger configurations (and those which I know will grow to more than 3 servers)I would prefer to use logon groups - aka Load Balancing.
Peter
Maybe you are looking for
-
Reloading Plug-In Page causes browser to hang during stress test on IE & NS
When an applet page is in the process of being loaded using the Java Plug-In and a second request is made to reload that applet or a new applet several times in succession, the browser hangs. Is there a work around for the Java Plug-In version 1.3.1.
-
Hi, We have going for NW 7.1 in few months for our PI. I have heard that SDM is not there in NW 7.1. Is it correct? If yes then how CTS+ will work as we have defined the SDM ID and passworin while configuration of CTS+ onout NW 7.0 system at present
-
Parameters while extending a page
Hi, I am trying to extend Personal Information page in SSHR to add a new region with location and organization details of the employee. But how can i get the person's employee number or personId in that page to join in my new query? Thanks in advance
-
[Solved] Python Tkinter Frame interaction
I am trying to have a form talk to another one as per exemple below. I cannot find a way to make this work. What am I doing wrong or missing from tkinter import * from tkinter import ttk class FirstFrame(): def __init__(self,root): self.root=root s
-
Fluid grid problem design view
Need Help, Dreamweaver CC, operating on Windows 7 64 bit My design view panel is set to 480 x 800 From the CSS Designer Panel, I select my fluid_grid.css from the sources section I select GLOBAL from the @Media section For some odd reason, my mobile