Hello everyone,
I have silly problem in my scenario with UTM, I will first describe my network because I wan't you to understand what I want to achieve before you tell me something like "Turn on uplink balancing".
Ok, so i have a company with two locations, both locations have internet connection and local networks.
Location A: I have 2 ISP at this location attached to Sophos UTM, they are configured for uplink balancing in active/active mode. I also have fiber connection to location B using third ISP that's providing 1Gbps between locations that is used to connect those networks.
Location B: At this location I have only 1 ISP attached to Cisco 2921, and I also have already mentioned fiber connection to location A. Because this (B) location have only ADSL 15/1 Mbps I decided to send all traffic to location A via fast fiber 75/75 Mbps link. Other reason for doing this is to get equal protection of all devices at both locations, because only location A have Sophos UTM SG330. At this location I configured Cisco router (L3 switch in this case) to check fiber connection via location A by sending ping to DNS server of a fiber ISP, and if ping to DNS server fail, L3 switch thinks that there is no Internet at location A and route traffic to 2921 router with ADSL Internet connection and everything works just fine. I tested this and everything is working as it should.
Now I came into a problem. I want to create a failover in case if I lose both Internet connections at location A. Location B will figure out that location A lost Internet and send traffic to Cisco, but I want UTM to also send all traffic to location B while Internet is down. At first I was thinking it's going to be easy to achieve something like this. I went to Interface configuration and changed interface that is connecting me to location B to also include default route, and after that I added that interface in Uplink Balancing as standby interface, and same second I have lost connection between locations because when I put that interface to uplink balancing as standby interface, UTM instantly shutdown that interface because other uplink interfaces are still up. Problem is that I want to use this fiber as my uplink ONLY when I lose both ISP-s at location A, but I need that fiber connection active always for other traffic between locations.
Now I'm thinking what will happen if I add this interface in active mode also, but i set Weight to 0? Does this mean that UTM will keep this interface UP but it will not use it to send Internet traffic to this interface while other 2 ISP-s are up, or it will send small portion of traffic via this interface. Sending Internet traffic from A to B location is only acceptable if we lose both ISP-s at location A.
I also tried adding default route to fiber connection with bigger metric, but I'm not able to create default route in Interface/Static Routes, when I put AnyIPv4 in destination UTM just doesn't allow this.
Am I missing something while there is a simple solution to my problem, or this is really hard to achieve?
Reason I'm posting question is because I already broken connection in production (for 2 minutes :D) when I added this interface as backup, so I can't test configuration in production anymore, and I want to hear others before I decide to change something again.
Thanks everyone in advance!
This thread was automatically locked due to age.