USG110 - WAN Failover - Policy Routes vs. WAN Trunk settings
- WAN Trunk procedure: https://www.youtube.com/watch?v=jogTfujoHkI
- Policy Routing: https://www.youtube.com/watch?v=6XhyZ3KWaxc
Best Answers
-
Hi @USG_User
If connectivity check function is disabled.
WAN trunk and policy route rule could failover to other interface when selected interface is physical link down.
WAN trunk -> failover to passive interface.
Policy route -> ignore policy route rule from table.
The only different is policy route priority is higher than WAN trunk.
I will recommend to use connectivity check.
It could check your network connection healthy but not only physical link.
You can check google DNS server than should without unavailable issue.
And you can configure check sensitivity in Interface setting or policy route rule.
0 -
Hi @USG_User
WAN trunk failover is only works during when connectivity check fail or interface physical link down.
When system detected all of Active interfaces are linking down, then traffic will pass through to Passive interface automatically.
WAN trunk load balancing will always work on all of “Active” interfaces.
If you selected “spillover” algorithm. The traffic will transmitted to 2nd priority interface when 1st interface loading has full.
If your ISP sometimes unable transmit data to internet successfully. Then your case will much fulfill “Failover”.
And also have to enable connectivity check for check network healthy….since your physical link may still alive.
0 -
Hi @USG_User
Yes, after primary interface connection is back then new session will pass through by primary interface continually.
The old session and traffic will transmitting by passive interface until it is timeout.
Of cause you can enter cli command to flush all of sessions exist on device.
Router# debug conntrack flush0
All Replies
-
Hi @USG_User
If connectivity check function is disabled.
WAN trunk and policy route rule could failover to other interface when selected interface is physical link down.
WAN trunk -> failover to passive interface.
Policy route -> ignore policy route rule from table.
The only different is policy route priority is higher than WAN trunk.
I will recommend to use connectivity check.
It could check your network connection healthy but not only physical link.
You can check google DNS server than should without unavailable issue.
And you can configure check sensitivity in Interface setting or policy route rule.
0 -
Thanks a lot Stanley for your explanations. Appreciated.Which event is being observed when using WAN Trunk Failover with active/passive WAN without Ethernet Connectivity Check? Does the physical link has to be dead firstly, that USG is switching over to WAN2?Or is "Spillover" also working fine (without connectivity check) when WAN1 interface isn't physical dead but ISP's backbone failed and nothing can be transmitted? (which is normally not a Spillover scenario)I think, without connectivity check the USG is only able to switch to another WAN, in case it detects a dead interface. But in most cases the interfaces are not completely dead since the next hop/gateway is still running. That's why the connectivity check is important. Is this correct?0
-
Hi @USG_User
WAN trunk failover is only works during when connectivity check fail or interface physical link down.
When system detected all of Active interfaces are linking down, then traffic will pass through to Passive interface automatically.
WAN trunk load balancing will always work on all of “Active” interfaces.
If you selected “spillover” algorithm. The traffic will transmitted to 2nd priority interface when 1st interface loading has full.
If your ISP sometimes unable transmit data to internet successfully. Then your case will much fulfill “Failover”.
And also have to enable connectivity check for check network healthy….since your physical link may still alive.
0 -
Will the USG continue to check the active WAN1 line after connectivity check on WAN1 failed and USG switched-over to passive WAN2 line? Means, does the USG automatically switch back to WAN1 as soon as it is available again?
1 -
Hi @USG_User
Yes, after primary interface connection is back then new session will pass through by primary interface continually.
The old session and traffic will transmitting by passive interface until it is timeout.
Of cause you can enter cli command to flush all of sessions exist on device.
Router# debug conntrack flush0
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 141 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.5K Security
- 216 USG FLEX H Series
- 262 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 243 Service & License
- 382 News and Release
- 81 Security Advisories
- 27 Education Center
- 8 [Campaign] Zyxel Network Detective
- 3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight