This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Uplink Balancing - two routers on same subnet

Hello,

I am trying to configure our UTM to work with our dual WAN office routers.  We use BGP multihoming for 2x Ethernet WAN connections from 2 different ISPs.  Right now, the routers are configured with Cisco HSRP, advertising a single virtual IP address of which our UTM has set as its Default Gateway.

But, I'm more interested to see if the UTM can handle the uplink balancing.  We do have a switch between the UTM and the routers, and so each router has a physical interface to the switch and there is a single physical interface from the UTM plugged into the switch.  Both router interfaces are in the same VLAN and same subnet (as is the HSRP VIP).

What I'm struggling with is, I'd like to setup Uplink Balancing but it seems I cannot do that with my two router interfaces.  The router interfaces are 192.168.255.2 and 192.168.255.3, with the HSRP VIP being 192.168.255.1.  The UTM interface is 192.168.255.254 and its GW is set to 192.168.255.1.  What I'd like to do is setup uplink balancing on 192.168.255.2 and 192.168.255.3, and then I can remove the HSRP VIP.

Soooo... how do I configure uplink balancing in the UTM when both uplink IPs are on the same subnet, and I have only one physical interface from the UTM going toward the WAN?  I think what I want is to balance uplinks based on IP address, not on interface..

Or, Is this called multipathing?

Cheers

SAM



This thread was automatically locked due to age.
Parents
  • I'm not sure I see the picture, Sam, but...

    It turns out that WebAdmin can handle what you want as the configuration daemon is smart enough to create the necessary rules in iptables.  In fact, the Default Gateway in an Interface definition doesn't need to be in the subnet of the primary address.  You can make the subnets /32.  Even if you made both interfaces /30, I don't think you would have any problems.  Let us know your result!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I'm not sure I see the picture, Sam, but...

    It turns out that WebAdmin can handle what you want as the configuration daemon is smart enough to create the necessary rules in iptables.  In fact, the Default Gateway in an Interface definition doesn't need to be in the subnet of the primary address.  You can make the subnets /32.  Even if you made both interfaces /30, I don't think you would have any problems.  Let us know your result!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data