UTM Community,
I’ve recently received a SG310 and have begun the initial prep before deploying it to the production network.
I would appreciate some guidance in regards to the setup of multiple WAN interfaces.
Currently there are 3 ADSL modem/routers, each used for a particular purpose.
1. General (primary) internet for staff
2. Cloud service (dedicated internet line for department who relies on solid connection for a cloud service)
3. Guest internet access
I will be changing the modem configurations to bridge mode and setting up PPPoE interfaces on the UTM and will recreate the existing port redirection rules on the modems.
I envision having the 3 WAN interfaces listed as “active interfaces”, but would like some assistance in regards to their actual configuration to preserve the existing traffic separation.
I think I need to create 2 new “network” definitions for the “cloud subnet” and the “guest subnet". Because currently there is only the one “internal” network (default).
I believe I should then be using “Multipath Rules” to achieve the traffic separation from the UTM out to either of the 3 modems, correct?
I create a new rule, source “internal” – service “all” – destination “all” – interface persistence “By Interface” – Bind interface “General”.
Second rule, source “cloud network” – service “all” – destination “all” – interface persistence “By Interface” – Bind interface “Cloud”.
Third rule, source “guest network” – service “all” – destination “all” – interface persistence “By Interface” – Bind interface “Guest”.
Is the above correct?
Documentation states that if an interface should fail, it would fall back to “by connection”, so ideally services would continue to work despite temporarily going out of the wrong internet connection. Is that right? What does a "connection" actually refer to?
Also in regards to “masquerading” do I need to setup additional rules for the new network definitions created (cloud and guest)?
At the moment there is only one rule for “Internal (Network)” > “Uplink Interfaces”.
Should I be adding a rule for “Cloud” > Uplink Interfaces and “Guest” > Interfaces too? Does the interface need to be changed from “uplink interfaces” to a specific interface (e.g. cloud internet/guest internet) ??
Appreciate some guidance on this.
Thankyou
This thread was automatically locked due to age.