Dual Wan and port routing

Hi,
I am setting up a configuration with SA520W and 2 Wan, in load balancing. But I face a problem that I could not understand.
Traffic is HTTP, SIP and 2 servers.
Servers are for a VPN tunnel and a mail server with ActiveSync
Both services absolutely need port 443 on the external IP, and that's one of the dual wan reason.
The 2 wan are running, load balancing mode is enable and NAt routing in firewall tab as follow :
443  Enabled     WAN     LAN     ALU_OpenVPN     ALLOW always     Any         192.168.0.150     WAN1     Always    
443   Enabled     WAN     LAN     ActiveSync     ALLOW always     Any         192.168.0.254     WAN2     Always 
If load balanced
Port 443 is NOT routed from wan1 to 192.168.0.150
Port 443 is routed from wan2 to 192.168.0.254
If only WAN 1
Port 443 is routed  from wan1 to 192.168.0.150
If only WAN 2
Port 443 is routed  from wan2 to 192.168.0.254
In fact I did other testing and no port routing with WAN1 when load balancing is enable, even on port that is not used at all on Wan2.
With a FTP filezilla server, it's OK if on wan2, and it stop before logging if on a wan1 (on laod balancing, ok on both case if only one wan)
Firmware : latest 2.1.18
Any Clue ??

Hello,
I confirm, there is a strange behaviour.
Simple test :
Dual Wan configured.
A FTP server on the LAN (192.168.0.254) port 21
Firewall , ipv4 config :
WAN   to   LAN     FTP     ALLOW always     Any         192.168.0.254     WAN1
WAN   to   LAN     FTP     ALLOW always     Any         192.168.0.254     WAN2
Then some testing using a FTP client outside the LAN, connection from Internet.
Then, changing ONLY the Wan Mode :
1/ Use only single WAN port : Dedicated WAN
==> FTP connect through WAN1
2/ Use only single WAN port : Optional WAN
==>FTP connect through WAN2
3/ Load Balancing
==>FTP connect through WAN1
==>FTP DO NOT connect through WAN1
Is that a bug or do I have some strange stuff somewhere ?
I will pick up another SA520W from stock, brand new, update the firmware, configure the 2 WAN (invering the 2 provider just in case) and do the same test.

Similar Messages

  • Dual WAN and Log mail SMTP on RV082 ?

    I use a RV082 with dual Wan and I cannot configure two SMTP.
    Without authentication; a SMTP is specific of the provider.
    When WAN1 comes down, SMTP to be used is the SMTP corresponding to WAN2 and vice versa.
    Implementation of authentication with the mail server wil be useful.
    Possibility of two mail servers with indication of the corresponding WAN is also useful.

    I don't know how or if it's possible to set up two SMTP servers, but I know that may ISPs block SMTP traffic that is not directed to one of their SMTP servers.  You could try picking just one SMTP server, and find out if it can be conacted on a non-standard port.  A lot of SMTP providers allow for this.
    If you can configure a single SMTP server on a non-standard port, you should be able to conatct that SMTP server from anywhere on the internet because the traffic won't be blocked (at least not port-based blocking, which is what most ISPs use).
    So in a scenario where WAN1 is the ISP who owns the SMTP server and WAN2 is a diferent ISP that blocks standard SMTP traffic...
    1) If both WANs are working, SMTP traffic goes out WAN1.  No problem.
    2) If only WAN1 is working, SMTP traffic goes out WAN1.  No problem.
    3) If only WAN2 is working, SMTP traffic goes out WAN2, but is not blocked because it is on a non-standard port.  No problem.
    I hope that helps.

  • Sockets and ports - routing messages between machines? helpppp!

    Hi,
    I'm new to java and am hoping someone out there can help me, hoping this is an ok place to post this:
    If all you need to create a connection is an IP address and a port number, using streams...
    Can you route messages from A to B then from B to C, where A looks up C through B having a hash table which contains C's IP address and port number?
    And how in the first instance does B know about A's IP address? All the examples I've seen the IP address is hard coded?
    Thanks in advance!

    I'm not sure what you are really trying to do... Can you explain in more concrete terms? Are you writing a chat client + server or something like that?

  • RV82 Dual WAN and online banking. Packets from two IP's

    Hi all
    I have a RV082 set up with two different ISP's (load balancing). A while ago the users started to get problems with online banking. It looks like the bank system set up more than one "channel" to/from the end user, and that the bank systems will not accept that packets are coming from 2 different public IP's. I have solved this by binding all HTTPS traffic to WAN1.
    Is this a good solution or is there a better way to deal with this? I'm afraid this will "unbalance" my network as many services like Netflix and Youtube is HTTPS.
    Are there any other online services that may have problems with a load balancing setup?
    If WAN1 goes down. Will WAN2 start to transport HTTPS even though HTTPS is bound to WAN1?
    I also have a similar issue with alert mail from the router (goes to wrong ISP every second time), but this seems to be fixed in the last firmware:
    "Email account authentication is configurable for email alert."
    Thanks in advance
    Jone

    Hello Jone,
    Your solution is correct.  Certain types of secure connection like HTTPS or SSH will not work if you keep switching the source IP, because it breaks the three-way handshake.  To prevent that you setup protocol binding as you have.  You can do the same thing for any other traffic that always needs to go out a certain WAN port.  
    If the WAN connection you have selected to protocol bind traffic to goes down, it will failover to the other WAN until the connection recovers.  
    I haven't seen too many online services that have issues with load balancing, it is mostly with secure connections, namely HTTPS.  I did try to get Netflix into HTTPS mode, but I could never get an encrypted connection, but your best bet is to monitor and observe the network to see how it affects you.
    I want to say the line you are quoting has to do with configuring authentication to an SMTP server to send e-mail alerts, rather then selecting a WAN port to use, however if you protocol bind SMTP to the WAN you would like it to use that should no longer be an issue.
    Hope that helps,
    Christopher Ebert - Advanced Network Support Engineer
    Cisco Small Business Support Center
    *please rate helpful posts*

  • VPN and a Dual Wan router confusion

    I am running a Border Manager 3.9 server with a Dual Wan router supplying the 2 ISPs load balancing to a single NIC on the Border Manager Server. I want to try setting up a VPN.
    Whats the easiest most pain free way of doing this?
    Just wondering,
    [email protected]

    In article <[email protected]>, Rlmillies wrote:
    > Whats the easiest most pain free way of doing this?
    >
    Hah! Well, inbound traffic in general can be problematical on a
    dual-wan system.
    Here you have two issues, if the router is like ones I've worked on.
    First, load balancing. You can't (probably - this is based on my
    experience) set up a static NAT of one of the public IP addresses to
    the BM 'public' address and still load balance. My experience is that
    as soon as you do that, it forces both inbound and outbound traffic
    onto that particular WAN link, so it kills load balancing/failover.
    Which means you need to do port forwarding on the router for all the
    VPN ports. You will need TCP and UPD 353, and UPD 500 and 4500 inbound
    (and replies outbound). If using a site-site VPN, you also need TCP
    213 inbound.
    You will have to configure the VPN address in BMgr to use one of the
    WAN public IP's. The VPN will only work on that one WAN link.
    Craig Johnson
    Novell Support Connection SysOp
    *** For a current patch list, tips, handy files and books on
    BorderManager, go to http://www.craigjconsulting.com ***

  • LRT224 and Spotify/port forwarding on dual WAN set-up.

    Very pleased with the  LRT224, which was easy to set up (dual WAN, one cable modem, one VDSL). I'm using it for a small home-based business with several PC's, and it's worked a dream in the load-balancing mode.  My request is beyond my current technical knowledge, however: we have Spotify on one PC for "background entertainment". It's a total bandwidth-hog, so I'd like to set it up to use the slower of the two WANs (VDSL) only.  I'm something of a newbie to the techniques of port forwarding, so I'd be really grateful if someone could describe the steps to bond all Spotify inbound/outbound traffic to WAN2. Is this even possible...?  Thanks in advance - Steve

    You can define a specific IP addresses or specific application service ports to go through a user-assigned WAN for external connections via Protocol Binding. Just bind the MAC address of your device to an IP address to properly route traffic to the specific device by IP and MAC binding.

  • Using ASA 5510 and router for dual WAN Connections.

    Guys, neeed some help here:
    Context:
    1- My company has one ASA 5510 configured with Site-to-site VPN, Ipsec Cisco VPN and AnyConnect VPN.
    2- We use ASA to connect to the single ISP (ISP 1) for internet access. ASA does all the NATing for internal users to go out.
    3- A second link is coming in and we will be using ISP 2 to loadbalance traffic to internet (i.e. business traffic will go via ISP1 and “other” traffic will go via ISP2).
    4- A router will be deployed in front of the ASA to terminate internet links.
    5- No BGP should be used to implement policy (traffic X goes via ISP1, traffic Y goes via ISP2).
    Questions:
    How do I get this done, particularly, how do I tell the router, for traffic X use ISP1 and for traffic Y use ISP2? PBR is my friend?
    Since I will be having 2 public Ip Addresses from the 2 ISPs, how do I NAT internal users to the 2 public Ip addresses ?.
    Finally, which device should be doing the NATing? The ASA just like now or move NATing to the Router?
    Thanks
    Ndaungwe

    Hi,
    Check the below link, it gives information on trasperant fw config and limilations. Based on the doc, you may need to move the VPN /anyconnect to router as well. From the routr end you may be able to set up static routes pointing to diff ISP based on traffic needs but this will be compleicated setup and can break things. Wait for other suggestions or if possible stick to ASA to terminate both links and still route the traffic to diff ISPs (Saves the router cost as well).
    http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_configuration_example09186a008089f467.shtml
    Thx
    MS

  • Lrt224 dual wan router

    Hi im new in dual wan setup. Please help.
    Heres my problem
    Wan 1 dynamic globe telecom primary
    Wan 2 static pldt telecom
    Link failover mode
    1 router is plug in to lrt224 to serve wifi and my switch also plugin to the wireless wifi
    1 cctv dvr connected to lrt224 port 9000 webport 9100 with auto detect settings setup
    Now:
    Sometime cctv camera broadcast to public ip when switch to wan2 but sometimes cant show also
    Same way around with dynamic wan 1 as primary
    Solved!
    Go to Solution.

    Thanks Guys, its a big help.......

  • I want to know if Ican connect a print server (to print with several wireless printers) to the new airport express given that it has wan and lan ports. Tks!

    The print server that I want to connect allows me to choose among 2 usb printers and 01 serail port printer. It needs to be connected to a router through a lan port. Given that the all new airport express now come with a wan and a lan port, i want to know if I can connect this device to the airport express.

    You're welcome.
    Beware that while USB print servers are commonly available and inexpensive, finding one with a serial port is more of a challenge. Apple Stores in the US do not sell them. Call the iStore before going there.
    If you need recommendations for obtaining a print server with a serial port, let me know.

  • RV325 Dual WAN Router - Use only one IP

    I have a rv325 dual wan router. I have setup load balancing on the router, but I don't want one of the servers here being load balanced. How do i set it to only use a specific WAN while everything else is load balanced?

    Michael,
    I like to share link that will has a step by step screenshots on how to configure protocol binding. Your source ip will be server and Destination is whichever WAN you are shaping that traffic. Hope this helps
    Article ID: 4242
    http://sbkb.cisco.com 

  • Cisco RV320 DUAL WAN router USB setup with Telstra 4G MF823

    I am trying to setup Cisco RV320 DUAL WAN router to work with my prepaid Telstra 4G MF823 device. Could you please assist. My settings are as follows: InterfaceUSB2Connection Type:3G/4G PIN Code:Confirm PIN Code:USB Connection Status:3G/4G modem is not available.Access Point Name:telstra.internetDial Number:Username:Password:Enable DNSDNS Server (Required): 8.8.8.8DNS Server (Optional): 8.8.4.4MTU:AutoManualB

    Hi oz000,
    Unfortunately we don't have anyone here to assist with this particular issue. Our team here provides assistance for the device standalone, we ensure that the 4G device connects to the network and functions correctly on its own.
    -Matt W
     

  • Windows server with dual wan router

    Hello, I have a doubtful scenario to be addressed. We had our 2008 server running on a single internet connection, but since its not reliable and has down time we planned to get another one.  We also bought a
    DUAL WAN Router so that we get some of the IPs without the group policy applied for testing purposes. So if we run a DHCP
    server on the router instead of the Windows 2008 server, will it work? We need one internet connection as the main connection and the other as standby for continous internet access.

    Guys,
    This is getting difficult to follow the conversation.  Let me try to clarify,..this is way way simpler than what it is being made (as far as I can interpret the situation).
    1. The dual WAN is completely irrelevant to the situation.  It could easily be a single WAN (single ISP) and it wouldn't make any difference.
    2. The WAN Device is the "Firewall",...meaning it is the NAT device,..and the only NAT Device
    3. There is no VPN,...but if there were the VPN would have to be performed by the WAN Device, meaning that you would have had to purchased one capable of such.
    4. The private LAN, as far as I can tell from what I read, is a single subnet "flat" network. Hence there is no router, none, zero,...and there should not be.
    5. The result of #3 and #4 mean that RRAS should not be enabled on any server on the LAN anywhere.
    6. DHCP needs to be, or at least it is best to be, "Active Directory Aware". Therefore it should be run on the Domain Controller.  The WAN Device should have Client serving DHCP completely disable.
    7. Group Policy is applied to an OU. If a machine account is in such OU then the policy will be applied, if the machine account is not in the OU then it will not be applied.  GPOs should be applied to specific OUs,...not at the "root" of the tree. 
    The only policies that should be applied at the "root" are the Default Domain Policy and the Default Domain Controller Policy,..and those should never be touched and left at their "default" so that you have a place to return to if GPO things go badly. 
    Do not leave objects within the Default Containers (Computers, USers, etc). Always create one or more OUs (you can even nest them), move the objects into them, and Link (apply) the GPOs at that level.
    Hope this helps clarify things.
    Phil

  • I just bought a new iMac and I am using a apple air port router.  How do I connect mt windows PC to the air port router do I can move files

    I Just purchased a 21.5 iMac and connected it to the Internet using a apple air port router.  How do I connect my windows PC to my air port router so I can transfer files.

    It makes life easier to install the airport utility for windows.. which has a couple of different apps in it.. if you airport is new type then the utility is too old.. but is still valuable for Bonjour which provides network information for shared devices in the apple world to windows.. and a disk access agent..
    It will also help the Apple computer access shared directory in the windows computer.. nowadays this is pretty easy.

  • LRT224 - Dual WAN port forwarding

    Can you forward say port 80 from WAN 1 to IP and port 80 from WAN 2 to a different IP.?
    Also can you somehow select TCP & UDP instead off just one or the other?
    I just replaced 2 TPLink routers with LRT 214 & LRT 224 its all working well. Except the port forwarding
    Solved!
    Go to Solution.

    With LRT224, a port forwarding rule is applied to both WAN ports, and two rules are required if you want to forward TCP and UDP to the same internal IP.

  • 867VAE dual WAN SDSL and ADSL failover

    Hello,
    I have the 867VAE router, and I'm looking for configuration example to implement the SDSL as the primary WAN and the ADSL for the backup.
    Could you send me plz an example of configuration?
    Cheer
    BR
    A.Aziz

    Pleas see as bellow :
    AIST#sh ip route 0.0.0.0
    Routing entry for 0.0.0.0/0, supernet
      Known via "static", distance 253, metric 0 (connected), candidate default path
      Routing Descriptor Blocks:
      * directly connected, via Dialer1
          Route metric is 0, traffic share count is 1
    AIST#sh track 1
    Track 1
      IP SLA 1 reachability
      Reachability is Down
        3 changes, last change 03:14:29
      Latest operation return code: Timeout
      Tracked by:
        STATIC-IP-ROUTING 0
    BR

Maybe you are looking for

  • Merge a remote database table using dblink

    We have a merge statement running in source database which is merging to a table in remote database using db link. The remote table is partitonoed (interval) table.Source db is 10g and target is 11g. this merge statement is failing with error saying,

  • HT201412 Voice Memos quits/can no longer sync iphone 4 - linked problem

    Voice Memos quits after two seconds of opening AND can no longer sync phone iphone4 to itunes, tried resetting, but don't want to restore phone to factory settings as I have important recordings I want to use. Help!! I've taken itunes off computer an

  • Eye Dropper tool in After Effects Not working Properly

    I am using Adobe After Effects CS5 on a mac. And most all of the eyedropper tools in the software are not working properly. They always select a way different color than it should be. What is wrong? One day they just all decided to not work. Its real

  • File to multiple files scenario

    Hi there, I will try to explain my scenario. I pick up a file with several lines and I need to create one output file per line - <RECORD> + <LINE_ITEM> + <LINE_ITEM> + <LINE_ITEM> -</RECORD> I set up message mapping and interface mapping target to un

  • My Game Center went away after the last back-up. How do I get it back?

    My Game Center went away after the last back-up. How do I get it back?