Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAN link manager useless when using BGP?

We are using BGP as the routing protocol to our ISP who provides us with two indepent WAN links and gateways which we can use as active/active or active/backup as we like.

It seems that any setting in the Routing -> Gateway section of SFOS and the corresponding WAN link manager settings are complete ignored. The behaviour of the link decision for outgoing and icoming traffic seems to be solely depending on the BGP advertisements and not on the settings there (active/active or active/backup / weight etc.).

Is this how it should work? Why is BGP routing seemingly uncoupled from these settings? We cannot find any note in the documentation stating that this is the case.

Best regards.



This thread was automatically locked due to age.
Parents
  • I wrote some text about this:  Sophos Firewall: Routing in Sophos Firewall with SD-WAN PBR 

    Basically: SFOS uses the "old world" RFC routing (Static, Dynamic Routing etc) and can use SD-WAN Rules to workaround it.

    The WAN Link Manager is "simply the last straw" the firewall uses, when the other tables are not giving an answer. 

    But if you using eBGP, your route is likely already injected (0.0.0.0?) and being used before we use the fallback option.

    __________________________________________________________________________________________________________________

Reply
  • I wrote some text about this:  Sophos Firewall: Routing in Sophos Firewall with SD-WAN PBR 

    Basically: SFOS uses the "old world" RFC routing (Static, Dynamic Routing etc) and can use SD-WAN Rules to workaround it.

    The WAN Link Manager is "simply the last straw" the firewall uses, when the other tables are not giving an answer. 

    But if you using eBGP, your route is likely already injected (0.0.0.0?) and being used before we use the fallback option.

    __________________________________________________________________________________________________________________

Children
No Data