This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAN Link Failover - Limiting Bandwidth on Backup

I have a dumb question on the interaction of firewall rule settings and WAN failover rules. My particular network has three WAN links: One fibre, one cable and one LTE. The fibre and cable are both set to active, while the LTE is set as a backup which is activated when both fibre and cable are down. As the LTE connection is metered and a bit expensive, I'd like to limit bandwidth usage only to what is absolutely necessary when the backup LTE connection is activated.

The way I've attempted to do this is to create different firewall rules. For those that enable essential traffic, I've Set Edit User/Network Rule | Advanced | NAT & Routing | Primary Gateway to "WAN Link Load Balancing". For those that enable non-essential traffic, I've set the Primary Gateway to the fibre connection and Backup Gateway to the cable connection.

The reason I've done this is on the assumption that the settings in the firewall rules will override the settings in WAN Link Manager. In other words, I've assumed that for non-essential traffic, if the fibre connection fails (set as Primary), it will switch over to the cable connection (set as Backup), and if that fails as well then no traffic will be routed at all. Just wondering if that is indeed the case, or whether, notwithstanding the settings in the firewall rule, the LTE backup connection (as set up in WAN Link Manager) would still kick in. The corollary assumption is that the backup would kick in when the firewall rule is set to "WAN Link Load Balancing".

I found this post that addresses the topic to some extent but doesn't quite answer the question on how the set up of a backup connection in the WAN Link Manager interacts with the settings in the firewall rule. 

Any thoughts or suggestions on the above would be most appreciated.



This thread was automatically locked due to age.
  • FormerMember
    +1 FormerMember

    Hey  

    No need to put yourself down, I think this is a great question!

    That post you referenced is correct in regards to the feature request for configuring a QoS policy exclusively for the backup failover connection (within the same firewall rule).

    However, the way you have your firewall rules configured (different firewall rules for different port traffic), should disallow your defined non-essential traffic in the event of a failover to your LTE backup connection.

    I did want to mention that for certain traffic (VoIP), once this traffic has failed over to your backup LTE link, this traffic does not automatically fail-back over to your active link (once it is back up) until the session for that connection ends.

    I'd still advise to schedule downtime and test a failover to your LTE backup to ensure your configured rules are working as intended.

    Please keep me updated if you run into any issues.

    Regards,