Cisco SA520-K9 Administration Guide - Page 57

Configuring Auto-Rollover, Load Balancing, and Failure Detection, Networking, Internet, Connection

Page 57 highlights

Networking Configuring the Optional WAN 2 • If you are having problems with your WAN connection, see the Internet Connection, page 217 in Appendix A, "Troubleshooting." Configuring Auto-Rollover, Load Balancing, and Failure Detection If you configured two ISP links, one for the dedicated WAN and one for the optional WAN, you can configure the WAN Mode to determine how the two ISP links are used. You can choose from these features: • Auto-Rollover: Enable this feature when you want to use one ISP link as a backup. If a failure is detected on the link that you specify as the primary link, then the security appliance directs all Internet traffic to the backup link. When the primary link regains connectivity, all Internet traffic is directed to the primary link, and the backup link becomes idle. You can designate either the Dedicated WAN port or the Optional WAN port as the primary link. Figure 1 shows an example of Dual WAN ports configured with AutoRoller. Figure 1 Example Dual WAN Ports with Auto-Roller Dual WAN Ports (Before Rollover) WAN1 IP SA 500 yourcompany.dyndns.org X X WAN2 port inactive WAN2 IP (N/A) Internet Dual WAN Ports (After Rollover) WAN1 IP (N/A) SA 500 WAN1 port inactive X X Internet yourcompany.dyndns.org WAN2 IP 197401 • Load Balancing: Enable this feature when you want to use both ISP links simultaneously. The two links will carry data for the protocols that are bound to them. You can use this feature to segregate traffic between links that are not of the same speed. For example, bind high-volume services through the port that is connected to a high speed link, and bind low-volume services to the port that is connected to the slower link. Load balancing is implemented for outgoing traffic and not for incoming traffic. To maintain better control of WAN port traffic, consider making the WAN port Internet addresses public and keeping the other one private. Figure 2 shows an example of Dual WAN Ports configured with Load Balancing. Cisco SA500 Series Security Appliances Administration Guide 57

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Networking
Configuring the Optional WAN
Cisco SA500 Series Security Appliances Administration Guide
57
2
If you are having problems with your WAN connection, see the
Internet
Connection, page 217
in
Appendix A, “Troubleshooting.”
Configuring Auto-Rollover, Load Balancing, and Failure
Detection
If you configured two ISP links, one for the dedicated WAN and one for the
optional WAN, you can configure the WAN Mode to determine how the two ISP
links are used. You can choose from these features:
Auto-Rollover:
Enable this feature when you want to use one ISP link as a
backup. If a failure is detected on the link that you specify as the primary
link, then the security appliance directs all Internet traffic to the backup link.
When the primary link regains connectivity, all Internet traffic is directed to
the primary link, and the backup link becomes idle. You can designate either
the Dedicated WAN port or the Optional WAN port as the primary link.
Figure 1
shows an example of Dual WAN ports configured with Auto-
Roller.
Figure 1
Example Dual WAN Ports with Auto-Roller
Load Balancing:
Enable this feature when you want to use both ISP links
simultaneously. The two links will carry data for the protocols that are
bound to them. You can use this feature to segregate traffic between links
that are not of the same speed. For example, bind high-volume services
through the port that is connected to a high speed link, and bind low-volume
services to the port that is connected to the slower link.
Load balancing is implemented for outgoing traffic and not for incoming
traffic. To maintain better control of WAN port traffic, consider making the
WAN port Internet addresses public and keeping the other one private.
Figure 2
shows an example of Dual WAN Ports configured with Load
Balancing.
SA 500
yourcompany.dyndns.org
X
X
WAN2 port inactive
WAN2 IP (N/A)
Internet
Dual WAN Ports (Before Rollover)
SA 500
yourcompany.dyndns.org
X
X
WAN1 IP (N/A)
WAN1 port inactive
Internet
Dual WAN Ports (After Rollover)
WAN1 IP
WAN2 IP
197401