I've got two sites with newer Sophos UTMs (the 120 and the 220), both on the latest updates. Each has an interface connected directly through a wireless backhaul, each has an interface with local internet connection (two diff IPs to the web).
Ultimate goal: All web traffic local to their own internet connection, but fail over to the backhaul link if one goes down. Testing the "remote" site first because "primary" site in constant use (hard to schedule down time).
-setup "remote" backhaul interface w/ gateway of "primary" interface, setup firewall rules and static routes on both ends: "remote" site local connection and internet through "primary" site
-On the "remote" site, I add in the internet interface w/ gateway, it asks if I want uplink balancing, enable and put backhaul on top: the internet stops working.
-I disable automatic monitoring and add "primary" firewall: Internet back up (through primary over backhaul)
-Enable Uplink Monitor: Backhaul online, Internet offline
-Add google.com into monitoring host: Backhaul online, Internet online
-Add multipath rule (Any→Web Surfing→Any→Internet Interface): Internet now locally connected at "remote" site
-Unplug internet modem: fails over to "primary" site internet over backhaul
-Plug back in, wait 5 minutes: No change
-Turn off uplink balancing, rebuild: both online again, going through local internet at "remote" site
I tried this a few times and each time, the link wouldn't come back as "online".
I wanted to see what would happen if I added an IPSec connection and used the "action" under the uplink monitoring .
-The tunnel was tested and works, but turned off.
-Turned on rule to turn on IPSec when uplink goes offline.
-Unplugged the wireless backhaul: IPSec turns on and connects, but no internet (didn't spend much time trying to figure out why)
-Plugged in wireless backhaul: stays offline, even after several minutes
Is this something I'm simply doing wrong? I can't seem to get these to come back online. Any help is greatly appreciated.
This thread was automatically locked due to age.