Re: Again two ADSL lines, routing problems



Andrea Venturoli wrote:
Hello.
I have a setup where a FreeBSD box is connected to two ADSL routers: default gateway is set to the first and, in case of failure, is moved to the other one. This works perfectly for outgoing connections: in the event of the switch, I'll have to reconnect, but that's acceptable.

The problem is in the incoming connections: if I get one on the "backup" router, this will reach the server, which will however answer through its "default" router. Thus the remote client will see packets coming back from a different host and things won't work.
Just to be clear, the packets travel as follows (with source and dest IP in brackets):
Client (x.x.x.x) -> Backup router (y.y.y.y)
Backup router (x.x.x.x) -> Server (z.z.z.z)
Server (z.z.z.z) -> Default router (x.x.x.x)
Default router (v.v.v.v) -> Client (x.x.x.x)

So the client (x.x.x.x) connects to y.y.y.y (the backup ADSL public IP), but gets answers from v.v.v.v (the master ADSL public IP).


AFAIK there is no solution to this, but I tought I'd ask before giving my official opinion to my customer.
Perhaps there's some sort of hack we could use, that through ipfw/natd/other diverting daemon/whatever delivers answers based on the MAC address of the incoming connections (if the MAC address belongs to the backup router, use that for answers)... does anyone know?

You have to enforce simmetrical routing on your FreeBSD box.
You can use, for example, PF firewall Using such options and features
as labels and route-to/reply-to statemens.

Also it is possible with ipfw, but I prefer PF. :)

--
Sincerely yours,
Artyom Viklenko.
-------------------------------------------------------
artem@xxxxxxxxxxxxxx | http://www.aws-net.org.ua/~artem
FreeBSD: The Power to Serve - http://www.freebsd.org
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • [LONG - for experts] Configuring redundancy for a /29 public range
    ... I have a single site with two internet connections: ... Primary Line: RFC1483 SHDSL 4Mbit/symmetric ... Backup line: RFC1483 ADSL 2048down/512upload ... First router SHDSL: ...
    (comp.dcom.sys.cisco)
  • Re: ADSL Hard Wired House
    ... And my line will have the ADSL connection, ... My bedroom will of course have my phone line and the ADSL ... So you will either need to use two, or get a router with 6/8 ports ... Or use Wireless for two of the connections. ...
    (uk.telecom.broadband)
  • Re: windows xp home edition taking ages to boot up
    ... Glen I don't know what the Live Communication Server 2005 is let alone how to ... that I can't use the router off a usb lead anyway. ... that in network connections you have 1 local area connection is that right. ... Are all the latest Windows ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: TV service query ? ? ?
    ... a wireless router. ... Many routers allow up to 50 connections. ... a router with extended coverage. ... is to have users downloading r/t video, large video files, or other ...
    (alt.home.repair)
  • Re: Networking/Security Question...
    ... The router itself will be a Cisco 1721. ... >setup is very simple... ... XP sp2 having the firewall on by default. ... > # but deny established connections that don't have a dynamic rule. ...
    (freebsd-net)