WAN Failover Data Usage?
Anyway - setup is easy enough. Put in the activated LTE SIM, set the modem to bridge mode, and hook the network port to the WAN2 port on the Zyxel. Create the Trunk in Active/Passive mode and you have failover.
Here's the problem - we're seeing approximately 250MB of traffic going over the LTE modem every day (and it is remarkably consistent) - which adds up at $10/GB ($15/GB if you're on Verizon). That's $75/month just in *standby* data with the failover not even being used. The assumption was when WAN1 was online and WAN2 is set to passive - no data would go over it? Is it possible after failback that a long term connection stays up on WAN2 after everything flips back to WAN1? Haven't gotten a chance to WireShark the connection yet to figure out what the traffic is yet.
Has anyone else seen this?
Best Answers
-
Hi @itxnc,Here is the behavior of wan trunk.The same session is running on the same interface because of link sticking.The feature link sticking is enabled by default.There is no configuration for link sticking on GUI or CLI.The link sticking function is to stick the session on one of wan interface when destination address is the same until the session expires.Hence, even if the active interface is back, the old sessions still stick to the passive interface until the old session expires.This is to avoid the disconnection of some session-aware applications.New sessions will go through the active interface.You can also select other load balance algorithm for the passive interface.Here is the configuration for user configured wan trunk.In the configuration of active interface, remember to enable connectivity check with valid IP address.Set small values to trigger failover more quickly.5
-
Hi @itxnc,
The passive interface is activated only when all active interfaces fail.
If only two interfaces are in a trunk and one interface is set as passive, there is no difference between spillover and least load first because only one interface is set as active mode.
The difference between spillover and least load first is obvious when there are at least two active interfaces in the trunk: 2 active interfaces and 1 passive interface.
5
All Replies
-
Suspect it was a lingering connection. I had not checked the 'Disconnect Connections Before Falling Back'
I also had used the wrong algorithm. Initially we'd used a cellular modem- which the KB says to use Weighted Round Robin for:
https://support.zyxel.eu/hc/en-us/articles/360001743233-How-to-configure-the-3G-LTE-Interface-on-the-ZyWALL-USG-as-a-WAN-Backup-
But the WAN Failover article says you have to use Spillover:
https://support.zyxel.eu/hc/en-us/articles/360005480394-WAN-Failover-via-trunk-of-a-USG
One weird thing - the video says to set the WAN1 Spillover value to something very high (say 100000kbps), but if you have the Egress value reduced so BWM works, you can't set it any higher than that (in my case 12000kbps). Not sure if it matters or not...
Then another article says to use Least Load First...
https://support.zyxel.eu/hc/en-us/articles/360004076140-WAN-Failover-with-Mail-Alert-USG-Series-FW-4-10-
Go figure.. For now we're going to see how it works with Spillover and the spillover value at the max egress value (and 0 for WAN2). And disconnect connections on failback enabled.0 -
Hi @itxnc,Here is the behavior of wan trunk.The same session is running on the same interface because of link sticking.The feature link sticking is enabled by default.There is no configuration for link sticking on GUI or CLI.The link sticking function is to stick the session on one of wan interface when destination address is the same until the session expires.Hence, even if the active interface is back, the old sessions still stick to the passive interface until the old session expires.This is to avoid the disconnection of some session-aware applications.New sessions will go through the active interface.You can also select other load balance algorithm for the passive interface.Here is the configuration for user configured wan trunk.In the configuration of active interface, remember to enable connectivity check with valid IP address.Set small values to trigger failover more quickly.5
-
So in an Active/Passive scenario where you kill connections on fail back, is there any difference between Spill-over and least load?0
-
Hi @itxnc,
The passive interface is activated only when all active interfaces fail.
If only two interfaces are in a trunk and one interface is set as passive, there is no difference between spillover and least load first because only one interface is set as active mode.
The difference between spillover and least load first is obvious when there are at least two active interfaces in the trunk: 2 active interfaces and 1 passive interface.
5 -
Zyxel_Emily said:
Hi @itxnc,
The passive interface is activated only when all active interfaces fail.
If only two interfaces are in a trunk and one interface is set as passive, there is no difference between spillover and least load first because only one interface is set as active mode.
The difference between spillover and least load first is obvious when there are at least two active interfaces in the trunk: 2 active interfaces and 1 passive interface.
0 -
itxnc said:Suspect it was a lingering connection. I had not checked the 'Disconnect Connections Before Falling Back'
I also had used the wrong algorithm. Initially we'd used a cellular modem- which the KB says to use Weighted Round Robin for:
https://support.zyxel.eu/hc/en-us/articles/360001743233-How-to-configure-the-3G-LTE-Interface-on-the-ZyWALL-USG-as-a-WAN-Backup-
But the WAN Failover article says you have to use Spillover:
https://support.zyxel.eu/hc/en-us/articles/360005480394-WAN-Failover-via-trunk-of-a-USG
One weird thing - the video says to set the WAN1 Spillover value to something very high (say 100000kbps), but if you have the Egress value reduced so BWM works, you can't set it any higher than that (in my case 12000kbps). Not sure if it matters or not...
Then another article says to use Least Load First...
https://support.zyxel.eu/hc/en-us/articles/360004076140-WAN-Failover-with-Mail-Alert-USG-Series-FW-4-10-
Go figure.. For now we're going to see how it works with Spillover and the spillover value at the max egress value (and 0 for WAN2). And disconnect connections on failback enabled.
I've also tried with Policy Routes and albeit technically working fine, I could not find a way to disconnect connections on failover WAN when failing back as it is possible for the failover trunk. And this could either become costly or lead to a throttled through-put, depending on your LTE data subscription.0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight