This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Failover WAN not failing over

Hey guys,

 

So I have 2 WAN links - one is Active and one is Backup - set to failover if the Primary fails by TCP not hitting 4.2.2.2 on Port 80 after 5 sec.

My Primary WAN port is Port 3 and shows Disconnected

My Back up Port is Port 8 and shows Connected

 

No matter what I try I cannot get the XG to failover to the backup connection.

Even swapping Active and Backup will not make them work.

 

In the FW rules I have  Primary and Secondary connection but they should fail over.

 

What am I missing?



This thread was automatically locked due to age.
Parents
  • Hi 

     

    Try to keep the WAN link load balance in the Firewall rule and see if that works. It's interesting that traffic does not pass through the Port8 when Port3 is down. Have you created any additional static routes or advanced firewall rules in the backend?

  • Jaydeep said:
    WAN link load balance in the Firewall rule and see if that works.

     

    Hey Jaydeep - yes we tried that as well. Sophos support even created a rule and tried all they could.

     

    I strongly believe its an issue with two PPPoE connections and how the XG handles a change such as failover. This XG used to have a Static and a PPPoE and it has failed over fine.

    A few updates and a change to WAN and no failover.

    Another Level 2 session booked for Monday night

  • Hi,

    the issue being that while WAN link manager causes fail overs, it does not cause a DHCP (PPPoE) refresh on the failed link and if the secondary link has failed at some stage, the failover process fails to connect.

    This should be relatively easy to prove. To cheap modem/routers that can handle PPPoE and have their NAT function disabled. Set one up on each link and monitor for a couple of days. Try causing link to fail eg disconnect the PPPoE interface cable, then reconnect it, then do the same with the other modem PPPoE interface cable.

    Ian

  • rfcat_vk said:
    the issue being that while WAN link manager causes fail overs, it does not cause a DHCP (PPPoE) refresh on the failed link and if the secondary link has failed at some stage, the failover process fails to connect.

     

    Might have something to do with it - however the XG does failover to the secondary link and its Active. my RED device reconnects to the failover WAN fine and from the XG you can ping / resolve the internet.

    But anything on the LAN side of the XG gets a Firewall VIOLATION error - Sophos Support couldnt work it out and we set up specific rules to force the traffic via the failover WAN but it just got blocked by the Firewall.

    Left the Support guy scratching his head.

Reply
  • rfcat_vk said:
    the issue being that while WAN link manager causes fail overs, it does not cause a DHCP (PPPoE) refresh on the failed link and if the secondary link has failed at some stage, the failover process fails to connect.

     

    Might have something to do with it - however the XG does failover to the secondary link and its Active. my RED device reconnects to the failover WAN fine and from the XG you can ping / resolve the internet.

    But anything on the LAN side of the XG gets a Firewall VIOLATION error - Sophos Support couldnt work it out and we set up specific rules to force the traffic via the failover WAN but it just got blocked by the Firewall.

    Left the Support guy scratching his head.

Children