limawhiskey Posted February 5, 2018 Posted February 5, 2018 Hi All. Just looking for a bit of advice around back up connections. We have a leased line (200 M) as our sole connectivity at the moment, via our Smoothwall UTM. SLT are looking for a cheap, "ticks a box" backup option, i.e. ADSL. This is to allow access for staff to Gmail and other essential cloud services should we have a failure of the main link. Obviously in this scenario, with the reduction in bandwidth, we'd have to put additional manual measures in place, e.g. blocking access for pupils, blocking streaming services, etc. That's something I can write up and deal with on the day. Here's the question: we have the option for the ISP to set up a VRRP setup (i.e. transparent to us), alternatively we connect the secondary connection to our Smoothwall and configure the Smoothwall for load balance / failover. I'd be interested to hear what you would go for, if you think there's any advantage of one or the other, or if you think the different setups have little practical difference for solving the problem. TL;DR: Smoothwall load balancing or VRRP FTW?
Katy Posted February 5, 2018 Posted February 5, 2018 We have VRRP on our current connection, it "just works", however... I'd stay away from ADSL as the backup as we've found it's almost unusable, on our new connection we've gone with FTTC as the backup and it's worked out cheaper than the ADSL was as we've changed supplier. 1
limawhiskey Posted February 5, 2018 Author Posted February 5, 2018 (edited) I'd stay away from ADSL as the backup as we've found it's almost unusable, on our new connection we've gone with FTTC as the backup and it's worked out cheaper than the ADSL was as we've changed supplier. Thanks. I did advise this, but (a) it was not as easy (cheap!) to get FTTC and (b) as it's purely a box ticking exercise then I don't think requirements will be properly assessed until the day it fails. We seem to like learning the hard way! Do you get any notification of VRRP kicking in from a router / link failure? Edited February 5, 2018 by limawhiskey
Katy Posted February 5, 2018 Posted February 5, 2018 Thanks. I did advise this, but (a) it was not as easy (cheap!) to get FTTC and (b) as it's purely a box ticking exercise then I don't think requirements will be properly assessed until the day it fails. We seem to like learning the hard way! Do you get any notification of VRRP kicking in from a router / link failure? No, but we're with Virgin and they have things like imaginary account managers and a complete failure to be contactable in any way (including not letting us have online billing, so we have to wait for the "overdue demand" letter, reply direct with "send us the invoice then", then pay it).
SchoolsBroadband Posted February 5, 2018 Posted February 5, 2018 Using VRRP will allow you to move the real world IP address that was on the leased line router onto the ADSL / backup connection which is a plus if you've any services pointing to your external WAN IP's. Using VRRP also gives you two routers rather than one so in the event of hardware failure of the primary router then the secondary will kick in. Whether using VRRP or not it sounds like you've only one smoothwall box so if that goes bang then you're stuck with no Internet anyway... Dave 1
tom_newton Posted February 6, 2018 Posted February 6, 2018 VRRP is definitely a nice way to do this - but may be overkill, particularly if this is a tick-in-a-box. Smoothwall's failover will do what you need with no need to do anything "clever" with the DSL connection. You could also then get crafty and use bandwidth management to prioritise certain traffic on the failover line. If you're worried about 1 smoothie as a single point of failure, you can always go for an HA pair. 1
RobFuller Posted October 16, 2018 Posted October 16, 2018 What would peoples recommendation for backup connection be, I assume you would definitely get a connection from an alternative ISP in the event of a high level outage with your primary one or from your ISP with maybe VRRP? Are there any options in SW @tom_newton for basic gateway failover instead of LLB? (not a concern if the outbound traffic IP changes) Inbound traffic would need to be rerouted if using alternative ISP (different public IPs) but again there are many solutions for this.
tom_newton Posted October 17, 2018 Posted October 17, 2018 Yes Rob, you can use LLB as a straight up failover. Personally i'd try and find something over a different medium eg Virgin cable , plus Openreach FTTP, or find a local WiSP
RobFuller Posted October 19, 2018 Posted October 19, 2018 (edited) Yes Rob, you can use LLB as a straight up failover. Personally i'd try and find something over a different medium eg Virgin cable , plus Openreach FTTP, or find a local WiSP @tom_newton I tried your new chat feature on SW support (very handy) however they told me basic failover wasn't possible, could someone advise?? Edited October 19, 2018 by RobFuller
tom_newton Posted October 19, 2018 Posted October 19, 2018 Let me go find the chat. Can you pm me your details?
RobFuller Posted October 19, 2018 Posted October 19, 2018 Let me go find the chat. Can you pm me your details? Thanks, PM sent.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now