Jump to content

Recommended Posts

Posted

Basically the issue is this. We are currently in the process of moving ISP and that means a new range of IP addresses. My concerns over the temporary delay in incomming E-mail as DNS changes kick in. (well not me personally but "certain" people at work get shirty if E-mail isn't received instantly :rolleyes: )

 

So my I have a slightly hardware specifc question. I have a Netgear FVX538 firewall which usefullly has Dual WAN ports. The downside is that now is not the ideal time to get all experimental with my firewall so I need some advice on how to confgure it.

 

If I set it up in load-ballancing mode and configure each port for my old and new ISP does the second port remain active for incomming connections? i.e. can I set up firewall rules for port1 with my new mail servers IP address and Port 2 with my mail servers old IP address and stilll receive e-mail on both IP's while I wait for the DNS changes to perculate over the internet?

 

As I read the instruction manual it say that the load balancing is actually only applied to the outgoing connections but doensn't really mention incomming.

 

I currently have it set up to only use a single WAN port. I am assuming that the second port is "deactivated". Is this the case? Can I just plug in a connection to the second port and it still be active and thus accept incomming traffic?

 

Any suggestions would be appreciated.

Posted
Stuart, what are you using for email filtering? If you use an external service (such as webroot / EMF) then you might be able to get them to extend the time they store prior to forwarding messages on. There are a few other things this sort of service can do but rather than go on if you don't have it can you give any other details about who holds your DNS, etc to see if there is something else which can be done to smooth the transition.
Posted
May also be worth temporarily changing the TTL settings in the DNS down to the minimum well in advance of the switch-over. That way the changes should propagate a lot more quickly when the time comes?
Posted

Presuming you have had a look at ftp://downloads.netgear.com/files/FVX538_RM_27Jan2010.pdf (section B-7)

For this you need to set up outbound in load-balancing mode and you need to set up the static routes for incoming traffic. Presuming that you already have static routes in place on your existing WAN connection these should just be duplicated on WAN2. Unless you have bound particular protocols to a particular WAN port then the response to inbound traffic should go out the same port. Just remember to backup the config (granny, eggs, sucking, blah, blah, blah)

Posted
May also be worth temporarily changing the TTL settings in the DNS

 

Seconded. When I've had sufficient control of DNS I've always done that e.g. 24 hours => 20 min TTLs a couple of days prior to significant IP address changes and it's always been worthwhile. Hasn't always done what it was supposed to everywhere because of some "interesting" configs out there on the net, but it certainly tends to help.

Posted
Presuming you have had a look at ftp://downloads.netgear.com/files/FVX538_RM_27Jan2010.pdf (section B-7)

For this you need to set up outbound in load-balancing mode and you need to set up the static routes for incoming traffic. Presuming that you already have static routes in place on your existing WAN connection these should just be duplicated on WAN2. Unless you have bound particular protocols to a particular WAN port then the response to inbound traffic should go out the same port. Just remember to backup the config (granny, eggs, sucking, blah, blah, blah)

 

Yes that was what I was reading last night. It's B-9 where it talks about the incoming traffic. Essentially I am looking to make both "public". I think it will be OK, it's just having not done it before I'm not feeling confident. Will probably just have to "suck it and see".

 

To be honest I'm not actually looking to load ballance the connection as I want to be using our new faster internet. I just need two active outside ports for incomming connections.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...