This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

routing questions for multiple inbound lines

Hi, a friend is running Astaro (7.5 atm), and wants to add a second Time Warner cable line.

Each line has 5 static IPs.

We will be building a new firewall with Astaro 8.0 or 8.1 Essential and a NIC for each line, plus one INT network.

Most of the EXT IPs will need to be routed to different internal IPs for web sites.

Questions:

1. If we only use DNAT+SNAT, will that be enough to make sure that outbound traffic goes out the desired interface (based on the SNATs)?

2. Or do we need to use PBR or something else?

3. I assume I need to set the gateway for each EXT IP (they are different gateways, fortunately).

Thank you,
Barry


This thread was automatically locked due to age.
Parents
  • This is something that would be most easily handled by using the uplink balancing and multipath rules on the Astaro... I believe you do have to have the Network Security subscription on the unit, though, I don't think the Essential Edition enables these features.

    You may be able to accomplish some of this manually using Policy based routes.  I've never really tried this, as the Astaro really doesn't like having more than one default gateway configured, unless you have Multipath enabled.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Reply
  • This is something that would be most easily handled by using the uplink balancing and multipath rules on the Astaro... I believe you do have to have the Network Security subscription on the unit, though, I don't think the Essential Edition enables these features.

    You may be able to accomplish some of this manually using Policy based routes.  I've never really tried this, as the Astaro really doesn't like having more than one default gateway configured, unless you have Multipath enabled.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data