A. WAN1/WAN2 Interface and LAN NAT/Routing host. B. VPN Host and LAN NAT Host. C. An example using Part A and B

Podobne dokumenty
Instrukcja konfiguracji usługi Wirtualnej Sieci Prywatnej w systemie Mac OSX

Stargard Szczecinski i okolice (Polish Edition)

Tychy, plan miasta: Skala 1: (Polish Edition)

Katowice, plan miasta: Skala 1: = City map = Stadtplan (Polish Edition)

Zakopane, plan miasta: Skala ok. 1: = City map (Polish Edition)

Wojewodztwo Koszalinskie: Obiekty i walory krajoznawcze (Inwentaryzacja krajoznawcza Polski) (Polish Edition)

Karpacz, plan miasta 1:10 000: Panorama Karkonoszy, mapa szlakow turystycznych (Polish Edition)

SSW1.1, HFW Fry #20, Zeno #25 Benchmark: Qtr.1. Fry #65, Zeno #67. like

POLITYKA PRYWATNOŚCI / PRIVACY POLICY

ARNOLD. EDUKACJA KULTURYSTY (POLSKA WERSJA JEZYKOWA) BY DOUGLAS KENT HALL

Warsztat: Infoblox DNS Firewall & DNS Infoblox Threat Analytics. Czyli jak w godzinę ochronić użytkowników.

MaPlan Sp. z O.O. Click here if your download doesn"t start automatically

OpenPoland.net API Documentation

Wojewodztwo Koszalinskie: Obiekty i walory krajoznawcze (Inwentaryzacja krajoznawcza Polski) (Polish Edition)

Helena Boguta, klasa 8W, rok szkolny 2018/2019

Miedzy legenda a historia: Szlakiem piastowskim z Poznania do Gniezna (Biblioteka Kroniki Wielkopolski) (Polish Edition)

ERASMUS + : Trail of extinct and active volcanoes, earthquakes through Europe. SURVEY TO STUDENTS.

OSI Network Layer. Network Fundamentals Chapter 5. ITE PC v4.0 Chapter Cisco Systems, Inc. All rights reserved.

Jak zasada Pareto może pomóc Ci w nauce języków obcych?

Camspot 4.4 Camspot 4.5

Dolny Slask 1: , mapa turystycznosamochodowa: Plan Wroclawia (Polish Edition)

Wojewodztwo Koszalinskie: Obiekty i walory krajoznawcze (Inwentaryzacja krajoznawcza Polski) (Polish Edition)

Revenue Maximization. Sept. 25, 2018

DODATKOWE ĆWICZENIA EGZAMINACYJNE

Dynamiczny DNS dla usług typu Neostrada przykład konfiguracji

Wojewodztwo Koszalinskie: Obiekty i walory krajoznawcze (Inwentaryzacja krajoznawcza Polski) (Polish Edition)

Blow-Up: Photographs in the Time of Tumult; Black and White Photography Festival Zakopane Warszawa 2002 / Powiekszenie: Fotografie w czasach zgielku

Weronika Mysliwiec, klasa 8W, rok szkolny 2018/2019

OSI Network Layer. Network Fundamentals Chapter 5. Version Cisco Systems, Inc. All rights reserved. Cisco Public 1

INSTRUKCJE JAK AKTYWOWAĆ SWOJE KONTO PAYLUTION

Pielgrzymka do Ojczyzny: Przemowienia i homilie Ojca Swietego Jana Pawla II (Jan Pawel II-- pierwszy Polak na Stolicy Piotrowej) (Polish Edition)

USB firmware changing guide. Zmiana oprogramowania za przy użyciu połączenia USB. Changelog / Lista Zmian

How to Connect a Siretta Industrial Router to a VPN Tunnel Using OpenVPN Protocol

Zdecyduj: Czy to jest rzeczywiście prześladowanie? Czasem coś WYDAJE SIĘ złośliwe, ale wcale takie nie jest.


Rev Źródło:

Egzamin maturalny z języka angielskiego na poziomie dwujęzycznym Rozmowa wstępna (wyłącznie dla egzaminującego)

User s manual for icarwash

Emilka szuka swojej gwiazdy / Emily Climbs (Emily, #2)

Steps to build a business Examples: Qualix Comergent

Zasady rejestracji i instrukcja zarządzania kontem użytkownika portalu

Installation of EuroCert software for qualified electronic signature

y = The Chain Rule Show all work. No calculator unless otherwise stated. If asked to Explain your answer, write in complete sentences.


Wybrzeze Baltyku, mapa turystyczna 1: (Polish Edition)

Extraclass. Football Men. Season 2009/10 - Autumn round

Instrukcja obsługi User s manual

* konfiguracja routera Asmax V.1501 lub V.1502T do połączenia z Polpakiem-T lub inną siecią typu Frame Relay

Instalacja i konfiguracja rouera ASMAX AR 904u. Neostrada, Netia

Miedzy legenda a historia: Szlakiem piastowskim z Poznania do Gniezna (Biblioteka Kroniki Wielkopolski) (Polish Edition)

Obsługa abonentów poprzez sieć L2 i L3, czyli ciąg dalszy centralnego BRASa w sieci

you see decision. oznacza to, Whenever kiedy widzisz biznes, someone once made Za każdym razem, który odnosi sukces,

Pomoc do programu konfiguracyjnego RFID-CS27-Reader User Guide of setup software RFID-CS27-Reader

Realizacja systemów wbudowanych (embeded systems) w strukturach PSoC (Programmable System on Chip)

SubVersion. Piotr Mikulski. SubVersion. P. Mikulski. Co to jest subversion? Zalety SubVersion. Wady SubVersion. Inne różnice SubVersion i CVS

Analysis of Movie Profitability STAT 469 IN CLASS ANALYSIS #2

Surname. Other Names. For Examiner s Use Centre Number. Candidate Number. Candidate Signature

Machine Learning for Data Science (CS4786) Lecture 11. Spectral Embedding + Clustering

Moxa Solution Day 2011

Jazz EB207S is a slim, compact and outstanding looking SATA to USB 2.0 HDD enclosure. The case is

Zarządzanie sieciami telekomunikacyjnymi

Rozpoznawanie twarzy metodą PCA Michał Bereta 1. Testowanie statystycznej istotności różnic między jakością klasyfikatorów

Angielski Biznes Ciekawie

Machine Learning for Data Science (CS4786) Lecture11. Random Projections & Canonical Correlation Analysis

Export Markets Enterprise Florida Inc.

PLSH1 (JUN14PLSH101) General Certificate of Education Advanced Subsidiary Examination June Reading and Writing TOTAL

Hard-Margin Support Vector Machines

Czy mogę podjąć gotówkę w [nazwa kraju] bez dodatkowych opłat? Asking whether there are commission fees when you withdraw money in a certain country

Bardzo formalny, odbiorca posiada specjalny tytuł, który jest używany zamiast nazwiska

USB firmware changing guide. Zmiana oprogramowania za przy użyciu połączenia USB. Changelog / Lista Zmian

Planning and Cabling Networks

Angielski bezpłatne ćwiczenia - gramatyka i słownictwo. Ćwiczenie 4

Czy mogę podjąć gotówkę w [nazwa kraju] bez dodatkowych opłat? Asking whether there are commission fees when you withdraw money in a certain country

Compatible cameras for NVR-5000 series Main Stream Sub stream Support Firmware ver. 0,2-1Mbit yes yes yes n/d

Asking whether there are commission fees when you withdraw money in a certain country

THE ADMISSION APPLICATION TO PRIVATE PRIMARY SCHOOL. PART I. Personal information about a child and his/her parents (guardians) Child s name...

Zmiany techniczne wprowadzone w wersji Comarch ERP Altum

General Certificate of Education Ordinary Level ADDITIONAL MATHEMATICS 4037/12

Wojewodztwo Koszalinskie: Obiekty i walory krajoznawcze (Inwentaryzacja krajoznawcza Polski) (Polish Edition)

X11R5. .Xresources. Pliki konfiguracyjne X-Windows. Zasada działania X11. .xinitrc. X protocol X server. X client. X library

USB firmware changing guide. Zmiana oprogramowania za przy użyciu połączenia USB. Changelog / Lista Zmian

FORMULARZ APLIKACYJNY CERTYFIKACJI STANDARDU GLOBALG.A.P. CHAIN OF CUSTODY GLOBALG.A.P. CHAIN OF CUSTODY APPLICATION FORM

Adresy IP v.6 IP version 4 IP version 6 byte 0 byte 1 byte 2 byte 3 byte 0 byte 1 byte 2 byte 3

USB firmware changing guide. Zmiana oprogramowania za przy użyciu połączenia USB. Changelog / Lista Zmian

Aktualizacja Oprogramowania Firmowego (Fleszowanie) Microprocessor Firmware Upgrade (Firmware downloading)

PSB dla masazystow. Praca Zbiorowa. Click here if your download doesn"t start automatically

Wroclaw, plan nowy: Nowe ulice, 1:22500, sygnalizacja swietlna, wysokosc wiaduktow : Debica = City plan (Polish Edition)

LEARNING AGREEMENT FOR STUDIES

Karpacz, plan miasta 1:10 000: Panorama Karkonoszy, mapa szlakow turystycznych (Polish Edition)

NEW CUSTOMER CONSULTATION QUESTIONNAIRE KWESTIONARIUSZ KONSULTACYJNY DLA NOWEGO KLIENTA

Życie za granicą Studia

Niepubliczne Przedszkole i Żłobek EPIONKOWO

No matter how much you have, it matters how much you need

TEORIA CZASU FUTURE SIMPLE, PRESENT SIMPLE I CONTINOUS ODNOSZĄCYCH SIĘ DO PRZYSZŁOŚCI ORAZ WYRAŻEŃ BE GOING TO ORAZ BE TO DO SOMETHING

Configuring and Testing Your Network

Few-fermion thermometry

Immigration Studying. Studying - University. Stating that you want to enroll. Stating that you want to apply for a course.

A n g i e l s k i. Phrasal Verbs in Situations. Podręcznik z ćwiczeniami. Dorota Guzik Joanna Bruska FRAGMENT


Dolny Slask 1: , mapa turystycznosamochodowa: Plan Wroclawia (Polish Edition)

Transkrypt:

This document introduces the Load-Balance/RoutePolicy. In real world, we need various kinds of routing rules to fulfill many different usages, and the Load-Balance/RoutePolicy is aiming to provide an integrated solution. There will be 6 parts in this note. In the first 5 parts we will talk about 1 usage each, and in the last part we will talk about the frequently asked questions. If you find your usage is not clearly described or is beyond these 6 parts, please do not hesitate to contact us for further assistance. The 6 parts are: A. WAN1/WAN2 Interface and LAN NAT/Routing host B. VPN Host and LAN NAT Host C. An example using Part A and B D. LAN NAT Host to Another LAN NAT Host via WAN E. VoIP Service to Muliti-PVCs VoIP Servers F. Frequently Asked Questions 1/24

In the Web UI, we put the Load-Balance/RoutePolicy in the top menu, and this is a screenshot from a Vigor2860: In the following contents, we will always use thisvigor2860 as the primary router to demonstrate the Load-Balance/RoutePolicy. 2/24

Part A. WAN1/WAN2 Interface and LAN NAT/Routing Host 3/24

1. We may take the DNS server 8.8.8.8 as the example, and the scenario is we want LAN 1 / LAN 3 clients reach 8.8.8.8 via WAN1. a. Tick to Enable. b. Choose the Protocol.The default value is any. c. Set the Source IP Start/End to limit the applied source IP addresses. If you choose any, this rule will be applied to all source IP addresses. In this case we use the IP addresses in LAN 1. d. Set the DestinationIP Start/End. If you choose any, this rule will be applied to all destination IP addresses. In this case we use 8.8.8.8 as the single destination IP. e. Set the Destination Port Start/End. If you choose any, this rule will be applied to all destination ports. In this case we use any. f. Choose the out going interface. In this case we use WAN1. g. Set the gateway IP. In this case we use the default gateway. 4/24

h. About Auto Failover To The Other WAN, tick this item so the traffics will be sent via another WAN automatically when WAN1 is down. i. There can be 2 possible usages: i. For LAN 1 NAT subnet, please choose force NAT, ii. For LAN3Routing subnet, please choose force Routing. j. Click OK to save. 2. We can see the traffic was sent out via WAN1, and with this result, the configuration is confirmed to be functional. 5/24

Note: To set destination IP address as an IP range,we may set the Dest IP as a range: Please note that the Port range may also be applied if required. 6/24

Part B. VPN Host and LAN NAT host 1. Sometimes we may have some VPN services, and we would like to set some rules so only certain user(s)/device(s)is eligible to use the VPN service. With Load- Balance/RoutePolicy, it can be done easily! 7/24

a. Set the Src IP. Here we set the IP address of the IPTV, so only the IPTV will be eligible to use the VPN service. To fix the IP address for the certain LAN client, please go to LAN>>Bind IP to MAC. b. We may do an nslookup to find the IP address of the Netflix server, and set the IP into Dest IP Start/End. c. Set the Destination Port Start/End. In this case we use any. d. Make sure the VPN tunnel is up, and then choose the VPN service in Interface. e. In this case, the Netflix service is available only when the VPN interface is up, and thus it s not required to tick Auto Failover To The Other WAN. 8/24

2. And now, we may do a trace route test to verify if the rule is applied: The trace route result shows the rule has been applied successfully, that the traffic to the Netflix server is sent via the VPN tunnel. 3. Or, if we want to limit that only certain users (for example, some managers in the company) may use the VPN service, we may set the profile like this: 9/24

Part C. An Example using Part A and B The requirements are: I. When LAN 1 clients access to the Internet, the router do NAT and the traffics go via WAN 1. II. When LAN 1 clients access to the Private Network, the router do Routing and the traffics go via WAN 2. III. When WAN 1 is down, traffics to the Internet should auto failover to WAN 2. IV. When WAN 2 is down, a LAN-to-LAN VPN tunnel should get established via WAN1 to the Private Network, and traffics to the Private Network should go via the VPN tunnel. 10/24

1. To fulfill the requirements, we edit 2 rules: 2. Index 1 fulfill the requirement II, a. When LAN 1 clients access to the Private Network, the traffics should be sent via WAN 2. b. Leave Auto Failover disabled, so when WAN2 disconnected, the traffics to the Private Network won t go via WAN 1 (should go via the VPN tunnel). c. Choose force Routing so the traffics will be routed to the Private Network. 11/24

3. Index 2 fulfills requirement I and III, a. When LAN 1 clients access to the Internet (we set the destination as any), the traffics should be sent via WAN 1. b. When WAN 1 is down, the traffics will be sent via WAN 2. c. Router should do NAT for the Internet browsing. 12/24

4. To fulfill requirement IV, please create a LAN-to-LAN VPN profile to the Private Network. a. Please choose WAN 1 only, since the VPN tunnel should only be dialed out to the Private Network via WAN 1. b. Please disable always on. When WAN 2 disconnected, the router will be triggered to establish the VPN tunnel automatically whenever there are traffics from LAN clients to the Private Network. c. The VPN server should be in the Private Network. 13/24

5. The rules and VPN profile have been configured, and nowwe may do some tests to verify: a. LAN client trace route to the Private Network The LAN client is able to access to the Private Network via WAN 2. b. LAN client trace router to the Internet (8.8.8.8). The traffics to the Internet are sent via WAN 1. c. Disconnect WAN 1, and the LAN client try to access to the Internet again. The traffics to the Internet are sent via WAN 2 this time. d. Make WAN 1 connected back again, and disconnect WAN 2 this time. The LAN client try to access to the Private Network: The first ping was timed out since the VPN tunnel was not established yet. The router was then triggered by the ping packets to establish the VPN tunnel, and started with the second ping, the LAN client was able to reach the Private Network via the VPN tunnel. 14/24

Part D. LAN NAT host to another LAN NAT host via WAN The scenario is that LAN 1 clients may access the FTP server in LAN2 via the WAN 1 public IP address. This is the WAN1 detail: 15/24

1. To do so, we may to set the rule so when LAN 1 clients trying to reach WAN1, they may go out via WAN2. a. Set the Src IPStart/End for LAN 1 clients. b. Set the Dest IP Start/End as the WAN 1 public IP. c. Choose the outbound Interface as WAN2. To do the NAT loopback, please choose WAN1 as the interface. d. Tick forcenat. 16/24

2. And then, we may set the Open Port rule for the FTP server: 3. Now, the function should be work! Here we use a PC in LAN2 running the HFS software as the FTP server, and a PC in LAN1 trying to access the FTP server via the WAN1 IP address: 17/24

Part E. VoIP Service with Multi-PVCs The Load-Balance/RoutePolicy also supports routing traffics according to different PVCs. The scenario is: I. LAN customers should go to the Internet via WAN1. II. IP phones may dial to SIP services in the Internet via PVC1 => DNS lookup may be required. III. IP phones may also be able to dial to the internal SIP service via PVC2. 18/24

1. To fulfill these requirements, we edit multiple rules: Now let s look into each rules. 2. Index 1 routes the traffics going from IP phones to the iptel server via WAN1. 19/24

3. When IP phones dialing to the iptel server, a DNS lookup may be applied, and thus we also need to edit rules to make sure the DNS lookup traffics going through WAN1. a. Before editing the routing rules, we need to make sure which DNS servers the LAN clients may use: b. And then, we may edit 2 routing rules for these 2 DNS servers: i. For DNS server 168.95.1.1 20/24

ii. For DNS server 8.8.8.8 21/24

4. Besides dialing to the iptel server, in the rest cases the IP phones dialto the internal SIP server, and the traffics should go via WAN5: Please note that the reason we left the Dest IP as blank is, the IP phone traffics should either go to the external server, or the internal one, and we have created multiple rules to make sure the traffics heading to the external server will go via WAN1, and now the remaining traffics should only go to the internal server via WAN5, and thus it s ok to leave the Dest IP as blank. 22/24

5. Now, the rules have been created well, andwe may do some tests to verify the routing: a. PC in LAN1 trace route to 8.8.8.8 The first hop is the gateway for LAN1 clients, and the second hop is the gateway for WAN1. b. SIP phone clients trace route to 8.8.8.8 The first hop is the gateway for SIP phones, and the second hop is the gateway for WAN1. c. SIP phone clients trace route to the another internal SIP client The first hop is the gateway for SIP phones, the second hop is the gateway for WAN5, and the third hop is another internal SIP client. 23/24

Part F. Frequently Asked Questions 1. I have more than 1 rules applying to the same LAN client(s), and I want to know how do these rules been respected? Answer: The first rule (according to the index number) been hit will be applied to the LAN client(s), while the rests will be ignored. 2. What is the priority between Firewall Rule, Inter-LAN Routing, Load- Balance/RoutePolicy, and Static Route? Answer: Firewall Rules > Inter-LAN Routing > * Load-Balance/Route Policy > Static Route *: To force traffic go between different LANs with Load-Balance/Route Policy rules, make sure the Inter-LAN Routing policy is configured properly in LAN >> General Setup, so the traffics can go between the LANs. 24/24