Multi-wan using separate firewalls
-
How would you set up WAN failover when your WAN connections are in two separate locations using two physically separate firewalls?
I've got internal routing between several buildings set up via OSPF, so traffic tends to flow to the nearest exit. But if one of the ISP connects should go down, traffic comes to a halt for select users until I manually adjust routing.
-
Impossible you say?
-
@kkrazyken you could use policy based routing and gateway groups. That's typically how multi-wan situations are load-balanced and failed over without something fancier like multihoming with BGP coordinated with your ISP(s). It's totally fine for outbound connections.
-
@whosmatt Interesting, I did not know that gateway groups could span multiple devices. How do I do add a gateway from another Firewall to the group? Or do I just create a group with one Gateway on each firewall?