- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-07-2014 04:04 PM
Hello all,
I had a question regarding PBF and how the failover works.
I have Internet circuit A and Internet circuit B, each through a different ISP. All traffic and VPN tunnels go through circuit A. I create a PBF rule to route web-browsing and ssl traffic only (using application-default) through circuit B. It is my understanding that failover occurs when it cannot ping the gateway or whatever IP address you specify. My question is, with my current scenario, which circuit is it using to initiate the ping? Say it uses circuit A to initiate the ping and that circuit fails. Wouldn't it try and failover the circuit even though circuit B is still up? Keep in mind that you cannot create a PBF rule for the ping application as far as I know.
11-07-2014 07:12 PM
Hi ClintL,
It takes egress interface of PBF rule. In this case its Circuit Bs Egress interface. Kindly refer following diagram.
Where is Policy Based Forwarding (PBF) Monitoring Traffic Sourced From?
Regards,
Hardik Shah
11-07-2014 05:12 PM
Hello ClintL ,
Could you please go through this DOC, it might give you the detail working flow for PBF with failover: How to Configure ISP Redundancy and Load Balancing
Thanks
11-07-2014 05:30 PM
Hi Clint,
It will use Circuit B to ping the address you specify. Once the address is not reachable it will fail back to Circuit A and your web-browsing and ssl traffic will also route through Circuit A.
Also when you define PBF, I would suggest configuring it using just the destination port 80 and 443 and not web-browsing and ssl, as application recognization will take few packets back and forth. Hope this helps. Thank you.
11-07-2014 07:12 PM
Hi ClintL,
It takes egress interface of PBF rule. In this case its Circuit Bs Egress interface. Kindly refer following diagram.
Where is Policy Based Forwarding (PBF) Monitoring Traffic Sourced From?
Regards,
Hardik Shah
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!