USG 210 - weird behaviour during WAN failover

Options
the_maxtor
the_maxtor Posts: 3 image  Freshman Member
Friend Collector
Hi community, this is my first post here.
I'm playing with a Zyxel USG 210, I'm trying to configure properly the WAN failover feature.
We have 2 WAN connection, WAN1 is pure ethernet with static IP, WAN2 is a PPPoE connection over VLAN 100, which parent's interface is WAN2. Connectivity check is also enabled on both WAN1 and PPPoE interfaces and the IP address to ping is 1.1.1.1

Default Trunk is a custom spillover Trunk, with PPPoE interface set as active and WAN1 as passive. 

We also configured 2 policy routes, for outbound connection for LAN clients. The first policy route said that traffic from LAN1 interface to any other destination should use PPPoE interface and the second policy route said that traffic from LAN1 interface to any other destination should use WAN1 interface.

When we completed the configuration we wanted to test the failover, in order to be sure it works properly. 
Scenario1: We remove cable from WAN2 (the internet connection we use as primary), no issue whatsoever, the firewall failover to WAN1 correctly
Scenario2: We remove cable from WAN1 (the secondary internet connection) the clients are not able to reach the internet anymore. Traceroute from clients stops at 1st hop (the firewall), PPPoE connection is still up, but for some reason the firewall removes both default routes for WAN1 and WAN2/PPPoE, even if it should remove only the default route of the disconnected interface: WAN1 . If we disconnect and connect again the PPPoE interface then the firewall add the default route for WAN2/PPPoE and everything starts working again. Why is that? Did anyone have this same issue?


All Replies

  • PeterUK
    PeterUK Posts: 4,674 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    The 1st policy route need to be set with a Connectivity check in advanced so that when that route fails the 2nd route takes over.


  • the_maxtor
    the_maxtor Posts: 3 image  Freshman Member
    Friend Collector
    Options
    I can assure you that is not the problem. On the system logs you can see that whenever an interface goes down the firewall correctly disables all the related policy routes. And by the way, everything works like a charm when we disconnect the primary WAN
  • Fred_77
    Fred_77 Posts: 147 image  Ally Member
    5 Answers First Comment Friend Collector Fifth Anniversary
    Options
    Hi @the_maxtor
    just thinking... you could try with only one route policy with "trunk" as next hop.
  • the_maxtor
    the_maxtor Posts: 3 image  Freshman Member
    Friend Collector
    Options
    Hey @Fred_77 what trunk should I set as next hop? A trunk with both WAN interfaces? Spillover? LFF? 

  • Fred_77
    Fred_77 Posts: 147 image  Ally Member
    5 Answers First Comment Friend Collector Fifth Anniversary
    Options
    Hi,
    ... the custom trunk you mentioned above... (ppoe as active, wan1 passive, spillover)
  • Zyxel_James
    Zyxel_James Posts: 839 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers
    edited June 2022
    Options
    Currently, we have two methods to achieve WAN failover, one is by WAN trunk, another is by policy route, and it seems you set up both methods at the same time, could you choose one of them and try again? Please refer to the YouTube tutorials.
    WAN trunk -> failover to passive interface. https://www.youtube.com/watch?v=jogTfujoHkI 
    Policy route -> ignore policy route rule from table. https://www.youtube.com/watch?v=6XhyZ3KWaxc


    Thanks,
    James
  • Divil
    Divil Posts: 1 image  Freshman Member
    First Comment
    Options

    Hello the_maxtor,

    did you solve this issue? We suffer of the same problem on Zyxel USG.

  • Zyxel_Melen
    Zyxel_Melen Posts: 5,039 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @Divil

    You can also create question post to ask. Remember to describe the details of your issue.

    Zyxel Melen