RV82 Dual WAN and online banking. Packets from two IP's

Hi all
I have a RV082 set up with two different ISP's (load balancing). A while ago the users started to get problems with online banking. It looks like the bank system set up more than one "channel" to/from the end user, and that the bank systems will not accept that packets are coming from 2 different public IP's. I have solved this by binding all HTTPS traffic to WAN1.
Is this a good solution or is there a better way to deal with this? I'm afraid this will "unbalance" my network as many services like Netflix and Youtube is HTTPS.
Are there any other online services that may have problems with a load balancing setup?
If WAN1 goes down. Will WAN2 start to transport HTTPS even though HTTPS is bound to WAN1?
I also have a similar issue with alert mail from the router (goes to wrong ISP every second time), but this seems to be fixed in the last firmware:
"Email account authentication is configurable for email alert."
Thanks in advance
Jone

Hello Jone,
Your solution is correct.  Certain types of secure connection like HTTPS or SSH will not work if you keep switching the source IP, because it breaks the three-way handshake.  To prevent that you setup protocol binding as you have.  You can do the same thing for any other traffic that always needs to go out a certain WAN port.  
If the WAN connection you have selected to protocol bind traffic to goes down, it will failover to the other WAN until the connection recovers.  
I haven't seen too many online services that have issues with load balancing, it is mostly with secure connections, namely HTTPS.  I did try to get Netflix into HTTPS mode, but I could never get an encrypted connection, but your best bet is to monitor and observe the network to see how it affects you.
I want to say the line you are quoting has to do with configuring authentication to an SMTP server to send e-mail alerts, rather then selecting a WAN port to use, however if you protocol bind SMTP to the WAN you would like it to use that should no longer be an issue.
Hope that helps,
Christopher Ebert - Advanced Network Support Engineer
Cisco Small Business Support Center
*please rate helpful posts*

Similar Messages

  • Dual WAN and Log mail SMTP on RV082 ?

    I use a RV082 with dual Wan and I cannot configure two SMTP.
    Without authentication; a SMTP is specific of the provider.
    When WAN1 comes down, SMTP to be used is the SMTP corresponding to WAN2 and vice versa.
    Implementation of authentication with the mail server wil be useful.
    Possibility of two mail servers with indication of the corresponding WAN is also useful.

    I don't know how or if it's possible to set up two SMTP servers, but I know that may ISPs block SMTP traffic that is not directed to one of their SMTP servers.  You could try picking just one SMTP server, and find out if it can be conacted on a non-standard port.  A lot of SMTP providers allow for this.
    If you can configure a single SMTP server on a non-standard port, you should be able to conatct that SMTP server from anywhere on the internet because the traffic won't be blocked (at least not port-based blocking, which is what most ISPs use).
    So in a scenario where WAN1 is the ISP who owns the SMTP server and WAN2 is a diferent ISP that blocks standard SMTP traffic...
    1) If both WANs are working, SMTP traffic goes out WAN1.  No problem.
    2) If only WAN1 is working, SMTP traffic goes out WAN1.  No problem.
    3) If only WAN2 is working, SMTP traffic goes out WAN2, but is not blocked because it is on a non-standard port.  No problem.
    I hope that helps.

  • Can you use Apple TV and source films/music from two different Macs in the home?

    Can you use Apple TV and source films/music from two different Macs in the home?

    not at the same time but yes.
    set up home sharing on both computers and Apple TV using the same Apple ID.
    Setting up Home Sharing on your computer
    Setting up Home Sharing for Apple TV (2nd generation)

  • Dual Wan and port routing

    Hi,
    I am setting up a configuration with SA520W and 2 Wan, in load balancing. But I face a problem that I could not understand.
    Traffic is HTTP, SIP and 2 servers.
    Servers are for a VPN tunnel and a mail server with ActiveSync
    Both services absolutely need port 443 on the external IP, and that's one of the dual wan reason.
    The 2 wan are running, load balancing mode is enable and NAt routing in firewall tab as follow :
    443  Enabled     WAN     LAN     ALU_OpenVPN     ALLOW always     Any         192.168.0.150     WAN1     Always    
    443   Enabled     WAN     LAN     ActiveSync     ALLOW always     Any         192.168.0.254     WAN2     Always 
    If load balanced
    Port 443 is NOT routed from wan1 to 192.168.0.150
    Port 443 is routed from wan2 to 192.168.0.254
    If only WAN 1
    Port 443 is routed  from wan1 to 192.168.0.150
    If only WAN 2
    Port 443 is routed  from wan2 to 192.168.0.254
    In fact I did other testing and no port routing with WAN1 when load balancing is enable, even on port that is not used at all on Wan2.
    With a FTP filezilla server, it's OK if on wan2, and it stop before logging if on a wan1 (on laod balancing, ok on both case if only one wan)
    Firmware : latest 2.1.18
    Any Clue ??

    Hello,
    I confirm, there is a strange behaviour.
    Simple test :
    Dual Wan configured.
    A FTP server on the LAN (192.168.0.254) port 21
    Firewall , ipv4 config :
    WAN   to   LAN     FTP     ALLOW always     Any         192.168.0.254     WAN1
    WAN   to   LAN     FTP     ALLOW always     Any         192.168.0.254     WAN2
    Then some testing using a FTP client outside the LAN, connection from Internet.
    Then, changing ONLY the Wan Mode :
    1/ Use only single WAN port : Dedicated WAN
    ==> FTP connect through WAN1
    2/ Use only single WAN port : Optional WAN
    ==>FTP connect through WAN2
    3/ Load Balancing
    ==>FTP connect through WAN1
    ==>FTP DO NOT connect through WAN1
    Is that a bug or do I have some strange stuff somewhere ?
    I will pick up another SA520W from stock, brand new, update the firmware, configure the 2 WAN (invering the 2 provider just in case) and do the same test.

  • OS X security and online banking

    Hello everyone.
    I've been using Macs for nearly a year and have never used anti-virus or spyware software. I currently feel secure in this.
    There was an article in The Sunday Times this morning about security of online banking.
    http://www.timesonline.co.uk/newspaper/0,,2770-2426237,00.html
    Some British banks have been found to less secure than others regarding phishing and fake websites. All my banking is done online and my bank was one of those listed as potentially being less secure. (The bank now says it's going to fix it.) The newspaper article goes on to say that banks will usually refund fraudulant transactions if you have up-to-date virus and spyware software and a firewall.
    I wonder where I would stand with my bank if something dodgy happened to my account and I'm not running anti-virus software. How much longer will I be able to sit back and smuggly say "I've got a Mac" (something I do quite a lot actually!) so I'm safe? Something to think about.
    Rachel

    Hi Rachel, I can't address the legal part of your question. Some British banks have been found to less secure than others regarding phishing and fake websites.Phishing and fake websites (mirrors) are more a function of user awareness. Never click on a link in an email if you suspect phishing, rather go to the banks website in your normal manner. You can also contact your bank to find out if they sent an email.
    I don't use any AV or Spyware software. That said, theorectically any Mac could be cracked/hacked. If you use common sense the odds against it happening are long.
    You can protect yourself by using your firewall and/or a hard wired router, downloading only from "trusted" sites, installing all security updates and being careful about what you give administrative power to.
    Don't use Limewire or any other P2P service to download your software, get it from reputable sources. In addition, always keep at least your users backed up, preferably a clone of your entire system on a separate disk. And put your sensitive passwords, bank accounts, credit card numbers in a "secure note" in a new keychain or in an encrypted folder.
    Enjoy your Mac
    -mj
    [email protected]

  • 10.5.6 Has broke Online Banking Access from Safari

    Since I updated my Intel imac with this update I can no longer access my online banking with BB&T, this is a very large Southeast Bank, when I log in, it just brings me to another screen, to log in again, no error message, I called the bank and of coarse they told me it's my fault, I must of forgot my password, anyway I talked to their online tech support, and they did tell me that they are aware that the update for the mac has broken the access to their site with Safari, they said I either had to use Internet Explorer or Mozilla, due to the fact that their site is no longer supported by Safari, due to the latest mac update.
    http://www.bbt.com
    Note: I also posted this at another site, where others have posted about the same problem with other online banking websites, not just BB&T

    I too am a user BB&T online banking and can no longer access the bank after upgrading to 10.5.6. I called the bank this morning and they told me they have been in touch with Apple regarding the problem. I started using Mozilla Firefox and was able to log into online banking. Since I'm a very long time PC owner and recently purchased my first Mac, I'm not impressed with this flop from Apple which I had greater expectations for problem free software. That's why I decided to leave Windows and the PC. Also, I had been a long time user of Mozilla browsers when I had the PC. Safari is starting to look like it's not going to be my browser going forward. What kind of testing is Safari subjected to at Apple? Mozilla has the backing of a large and knowledgeable creative community.

  • Kmymoney and online Banking (HBCI)

    Hi, I would need help to get kmymoney 0.8.8 working together with HBCI support. I got already aqbanking and its dependencies installed and there is an additional plugin needed by kmymoney called kmm_banking-0.9.3beta which I compiled directly into my system. So I am able to see the online banking entry in kmymoney but the plugin does not work properly, which means I can't connect to the bank.
    So if there is anyone who got it working or has an idea how to make hbci support properly available in the current kmymoney, that would be much appreciated. In case I omitted same necessary information you need to now in order to help solve the problem, let me now.

    http://kmymoney2.sourceforge.net/release-plan.html
    It's not implemented, yet. But it will be, that is just a matter of time..

  • Capturing packets from two server programs in single solaris box

    Hi,
    Greetings.
    I observe that snoop is not capturing packets exchanged between two server process which are running in a same solaris machine.
    Are there any options with snoop, so that it is possible to capture the
    packets between two server processes in a single machine ?
    Thanks in advance.
    BR, RK

    Snoop? No. Packets to the same machine never reach the DLPI layer which is where snoop is looking.
    There are some 'dtrace' scripts on Solaris 10 that attempt to view the contents as they go within the machine. They should work with most interfaces.
    I don't know of any good solution for Solaris 9.
    Darren

  • RTX Dual Phone and Online Number

    I'm planning on getting RTX Dual Phone with an online number to replace my land line. The requirements specify Broadband Internet connection (I have DSL service and a router with open ports).
    The requirements also state 'landline operator subscription'. What does this mean? My objective was to replace the landline?
    The RTX dual phone package comes with 2 handsets. How many will it support and where do I buy extra handsets.
    Can I set Skype on my computer to the same online number, so that it rings when my computer is on.
    thx
    Visitor John

    Hi, If you buy a Skype phone and an online number anyone who calls it either from a landline, mobile or Skype ID, the phone will ring. If you are signed on on another device be it a computer or IPhone app all devices will ring. As long as the Skype phone is switched on and has Internet connection it will be online 24 x 7. If you need any more info please get in touch.
    Feel free to contact us on Skype ID: tetra4comms
    or type 'Tetra4 Skype' in your search engine.
    Tetra4 - Putting Skype to Work.
    www.tetra4.com

  • Why can't I access my online banking site from my new computer. I can get into it with my old PC, but not my new MacBook Pro

    I can't remember what you do to open a link.  I'm in my bank site and want to open bill pay.  It says it opened in another tab but it isn't.  What the heck?

    nduttonca wrote:
    I can't remember what you do to open a link.
    You click on it. 
    Which os version are you using?  Which browser & version are you using?  If you are using Safari, post in its forum area.  A 3rd party browser, post in their forums. 
    Have you contacted the bank webmaster or tech support to determine that the issue is not on their end? 
    If your computer is "new" you have 90 days of free phone tech support from Apple.  Take full advantage of it and call Apple Care. 

  • Safari and Online Banking

    When is Safari going to join the 21st century?
    As IE has fallen off its perch - When will I be able to go on line to my Natwest bank account?
    I've aired this subject before but Sofari not a peep out of Safari.
    It is astounding that nothing has been done by Safari to rectify this problem which of their making.
    cheers
    Steve Hill

    When I contacted The Natwest Bank they told me that they had contacted Safari about the problem. It seems that Safari retains confidential information when the Natwest custumer logs out that IE and others do not retain, and until Safari changes that state then Natwest cannot/will not allow customers to be put at risk - and also themseleves no doubt.
    I have been told before that Firefox seems to be fine as is Mozilla (spelling?) but why should I move from Safari - may be I should move - in fact at some point I shall move if Safari cannot/will not solve the problem.
    I find it a bit much that IE works but not Safari. I bet if Jobs had his account at Natwest the problem would have been addressed - 26.
    Cheers
    Steve Hill

  • VPN and a Dual Wan router confusion

    I am running a Border Manager 3.9 server with a Dual Wan router supplying the 2 ISPs load balancing to a single NIC on the Border Manager Server. I want to try setting up a VPN.
    Whats the easiest most pain free way of doing this?
    Just wondering,
    [email protected]

    In article <[email protected]>, Rlmillies wrote:
    > Whats the easiest most pain free way of doing this?
    >
    Hah! Well, inbound traffic in general can be problematical on a
    dual-wan system.
    Here you have two issues, if the router is like ones I've worked on.
    First, load balancing. You can't (probably - this is based on my
    experience) set up a static NAT of one of the public IP addresses to
    the BM 'public' address and still load balance. My experience is that
    as soon as you do that, it forces both inbound and outbound traffic
    onto that particular WAN link, so it kills load balancing/failover.
    Which means you need to do port forwarding on the router for all the
    VPN ports. You will need TCP and UPD 353, and UPD 500 and 4500 inbound
    (and replies outbound). If using a site-site VPN, you also need TCP
    213 inbound.
    You will have to configure the VPN address in BMgr to use one of the
    WAN public IP's. The VPN will only work on that one WAN link.
    Craig Johnson
    Novell Support Connection SysOp
    *** For a current patch list, tips, handy files and books on
    BorderManager, go to http://www.craigjconsulting.com ***

  • Can I purchase from malaysia apple store with my online bank account without using credit card?

    hi,
    I want to purchase online an iPad2 from apple store in malaysia. I don't have credit card. I only have the online banking facility from my bank. Can anyone please tell me if its possible to use online bank transfer to apple store instead of using credit card? Please suggest any alternative method to pay online to Apple store. I didn't find any other payment method other than credit card in apple malaysia website.
    I will be waiting for the reply eagerly.

    http://store.apple.com/my/help/payments
    If you have further questions, I'd suggest calling the Apple Store.
    Regards.

  • Safari will no longer support my online banking, Bill Pay???Any solution?

    Anyone have problems with Safari and online banking , Bill Pay?

    jodee --
    Welcome to Apple Discussions.  We all volunteers here, other Mac users helping each other find solutions.
    So, yes, I had problems initially with my bank, and I found that if I refreshed the page (press the command/Apple key along with the letter " r " key), the bnk pages would kick in as usual.  I had to do that for a couple of weeks, but my bank finally caught up with the new Safari several weeks ago.
    Try the refresh page, and let us know how you're doing, OK?

  • HT5622 my stepdad used to use my phone and the imessage accounts have now joined together by mistake we don't know how it happened but is there a way we can separate the two accounts because we are able to read messages that are coming from two different

    hello can i please get some help, my stepdad used to use my phone a while ago, i deleted his old account from my phone, last night out IMessages merged without us knowing how it happened, he is able to read any messages that are coming into my phone through IMessage and also i am able to read his and this is happen from two different phone, i dont know how to fix  this or two separate the two accounts, is anyone able to help please

    Settings>Messages Send and Receive should only have the phone number and addresses checked that you want reaching that individual devices  If your step-dads number and email are checked just tap them it will remove the check.

Maybe you are looking for

  • CPF contribution is not deducting on AWS amount for retried employee.

    Hi, Issue reported: - CPF contribution is not deducting on AWS amount for retried employee. fyi -even though employee is separated his bonus will be paid in month of December I have checked the AWS wage type, the culmination class 3 is checked, as it

  • Hirerachical display in ALV report

    Hi all, I am using Fm as following for hirerachical display. CALL FUNCTION 'REUSE_ALV_HIERSEQ_LIST_DISPLAY'     EXPORTING       i_interface_check        = ' '       i_callback_program       = sy-cprog       is_layout                      = ls_layout

  • Ipad Charging & 30 pin connector

    Having used my Ipad for about 13 months with no problem, it suddenly has issues with charging. It will charge extremely slowly with the 10W charger that I have been using for the whole period, but it doesn't have the charging symbol over the battery

  • Y530 virtualization (Intel VT) [SOLVED]

    Hi all.I've developed VT activation procedure for Lenovo Ideapad Y530. But provided that your notebook corresponds to the following requirements: - Your CPU MUST support Intel virtualization Technology otherwise you'll get nonfunctioning laptop. - CP

  • ADD VALUES IN PL/SQL??

    My PL/SQL statement below doesn't return the desired outcome. below variables A, B, & C are declared as VARCHAR2 data type. D is declared as Number data type. select (to_number(A)+to_number(B)+to_number(C) INTO D from dual; I was expecting that D wil