data:image/s3,"s3://crabby-images/533ce/533ce88cb9bf28ddf7b4e1be46120c964e544386" alt="Open-Source-Load-Balancers1"
1.The purpose of the article
This article will show you how to configure Load Balancing using the SD-WAN feature for systems with multiple internet connections so that when one of the lines fails, the connection will not be interrupted.
2.Diagram
data:image/s3,"s3://crabby-images/be6e7/be6e7b2e291871804598b3786db0d649d47cfac1" alt=""
Details:
- There are 2 are connecting to Sophos firewall and running Load Balcing, ISP 1 internet connection connects to Port 2 of Sophos Firewall with IP 192.168.2.103 and Default gateway has IP 192.168.2.1.
- ISP line 2 is connecting to Sophos firewall at Port 3 with IP 192.168.2.117 and Default gateway has IP 192.168.2.1.
- Port 1 will be in the LAN zone of the Sophos firewall with IP 10.145.41.1/24 and has DHCP configured to allocate IP.
- Finally, Laptop 1 has IP 10,145.41.11/24.
3.Scenario
We will configure Load balancing for two internet lines, ISP 1 and ISP 2, with ISP 1 as the Active line and ISP 2 as the Backup line.
Then the traffic going to the internet will follow ISP 1 to access the internet.
Then we will turn off the ISP 1 connection to check if the device fails to failover the internet connection to the ISP 2 backup line like the load balancing configuration that we have configured.
4.Step to take
- Check internet ports.
- Configure ISP 1 connection as Active line.
- Configure ISP 2 connection as Backup line.
- Result.
5.Configuration
5.1.Check internet ports
We will go to Network > Interface and see that we currently have 2 internet connections at Port 2 and Port 3.
data:image/s3,"s3://crabby-images/074d7/074d7808007caa70177793c9ce6a17365cf436a4" alt=""
Next we go to Network > WAN link manager and see that these two lines are running in active mode and their weight is 1, which means each line is under 50% load.
data:image/s3,"s3://crabby-images/42a4f/42a4f660c162d5d6e70261360994d3d5c2f76a3b" alt=""
5.2. Configure ISP 1 connection as Active line
Click on the pencil icon at ISP line 1 to configure.
data:image/s3,"s3://crabby-images/5fbc7/5fbc7b58c0dc9e1f534f871a530ea10d79339f3d" alt=""
Configure with the following parameters:
- Type: Active.
- Weight: 1.
- Click Add at Failover rules to configure failover conditions.
data:image/s3,"s3://crabby-images/95aca/95aca6a68335b782db79d01e32e80a73295e7528" alt=""
We configure the Failover rule as follows:
- At Not able to Connect on the first line select PING – 192.168.2.1 – AND.
- At Not able to Connect 2nd line select PING – 8.8.8.8.
- Click Save.
These parameters have the effect that the device will ping to 2 IP 192.168.2.1 which is the default gateway of ISP lines 1 and 8.8.8.8 of google…
If the device pings successfully, the internet traffic will go through ISP line 1.
If the device fails to ping this 2 traffic, it will failover the traffic over ISP 2.
data:image/s3,"s3://crabby-images/23a9d/23a9d747c6a6112f7ac1ba886c40a9deda461024" alt=""
After configuration, the parameters of ISP 1 will display as follows.
Click Save.
data:image/s3,"s3://crabby-images/b0d91/b0d911d14110588c70f21fc719479301b2eb5456" alt=""
5.3. Configure ISP 2 connection as Backup line.
Similar to ISP 1 line, we also click on the pencil icon of ISP 2 to configure.
data:image/s3,"s3://crabby-images/40f0a/40f0a48c18f1e51adcafaf28d05b3115719f860c" alt=""
Configure with the following parameters:
- Type: select Backup.
- Activate this gateway*: select ISP 1
- Action on activation: select Inherit weight of the failed active gateway.
- Serve new connections throught restored gateway.
- Click Save.
data:image/s3,"s3://crabby-images/f91bc/f91bc87e3420da43fd61728d9becd52968e9da92" alt=""
The parameters that we configure for ISP 2 mean that if ISP line 1 is dropped, ISP 2 will inherit the weight parameter from ISP 1 and new traffic going to the internet will be redirected to ISP 2.
5.4.Result.
We will use laptop 1 to access the internet.
Then in the log viewer, we will see that the current outgoing internet traffic is going using Port 2 (ISP 1).
data:image/s3,"s3://crabby-images/3840f/3840f70e50f1fe117bb09d75d0256c067fa7d7bb" alt=""
Then we will perform ISP 1 disconnection to test failover.
To turn off we click on admin in the upper right corner of the screen select Console or you can access the console with Putty.
data:image/s3,"s3://crabby-images/c4971/c497170f6c03c1a030be9b88392eb6a4ad646dc4" alt=""
After pressing Console a new window appears press Enter then enter the password and press Enter again to login to the console of the device.
data:image/s3,"s3://crabby-images/538e0/538e065f7935698bf643f7d5e988280f39921bc0" alt=""
Type 5 and press enter to enter Device Management.
data:image/s3,"s3://crabby-images/12375/12375ceae6a61b75c59b8e3b45be224414b0f5cb" alt=""
Type 3 and press enter to enter Advanced Shell.
data:image/s3,"s3://crabby-images/a804b/a804b13a83108d3d32edd2bbfa76eac9bbc7f335" alt=""
Enter the command “ifconfig Port2 down” to disable this port.
data:image/s3,"s3://crabby-images/fa80c/fa80cb130fff86a675f45684233b237f6738a90b" alt=""
Then go back to the configuration page of the Sophos Firewall device, go to Network > WAN link manager we see the status of ISP 1 to turn red, which means it’s turned off.
data:image/s3,"s3://crabby-images/cbd0b/cbd0b61c63975b91fa20b8190a20d4f8af1b70bd" alt=""
Then we will access the internet using the browser and the result is still normal internet access.
This proves that failover happened when ISP line 1 was down.
To check we go back to the Log Viewer and see that the current internet traffic goes to Port3 ie ISP 2.
data:image/s3,"s3://crabby-images/ce097/ce09744ecd95ffbb3bc0ad0a33304a5ecb815d00" alt=""
Leave a Reply