In WRR Trunk Load Balancing, add "Bind all sessions from one IP" option on H series Zywall

AndreaRP
AndreaRP Posts: 2  Freshman Member

WRR distributes sessions among available WAN interfaces/lines.

However, this may have an adverse effect if multiple sessions from the SAME client are spread among WAN interfaces, effectively showing different IP addresses from the different interfaces. Some sites/apps/services require more than one session to be open, and the different origin of the connections trips some security alerts.

Some other manufacturers already have a "bind sessions from IP to interface": if checked, all sessions coming from one IP are bound to a single interface.

This reduces the effectiveness of the load distribution if there are just a few clients and only one of them opens a lot of sessions/transfers, but has a negligible impact on the distribution when there are more clients. At the same time, it solves the operatinal problems deriving from sessions "coming" from different WAN IPs

0 votes

Active · Last Updated

Comments

  • PeterUK
    PeterUK Posts: 3,605  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Wouldn't a routing rule works with wildcard FQDN like *.live.com?

    So a top rule would look like.

    Incoming LAN1
    Destination address *.live.com
    next hop WAN1

    So that when the client does DNS the routing rule uses a give WAN for IP's of *.live.com

    or you can have a client given source IP to use I give WAN.

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,854  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @AndreaRP,

    Thanks for sharing this idea. I have let our product team know this request and we will monitor this post, the comments and the votes, to evaluate this idea.

    Zyxel Melen