ScreenOS Firewalls (NOT SRX)
Reply
New User
sxanness
Posts: 1
Registered: ‎11-01-2010
0

Load Balancing with SSG-140

I am having a hard time finding direct step by step instructions on how to configure load balancing with my SSG-140.  Is it even possible?  

 

I have an ADSL connection and a T1 Connection.  The ADSL is new and that is what we are using right now; however, we are still in contract for another year on our T1 and I would like to make use of it with Load Balancing if possible.  The assumption here is that if I can get load balancing configured with the T1 and the ADSL that after the T1 contract expires we can replace it with another ADSL line.  

 

Some sites have talked about policy based routing where I select what type of traffic I want to send over each interface, but a true load balancer would be nice if the Juniper can do it. 

 

If anyone can point me to a good source of documentation that would be greatly appreciated or if you have any suggestions on how I can make this work the best that would also be appreciated. 

Distinguished Expert
spuluka
Posts: 2,808
Registered: ‎03-30-2009
0

Re: Load Balancing with SSG-140

True loadbalancing is not in the SSG feature set.  But you can get an approximation of this by setting up both internet services with a default route that has the same metric and preference.  The firewall will round robin the connections then that use these two services.

Steve Puluka BSEET
Juniper Ambassador
Expert Network Security Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
ACE PanOS 6
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Contributor
TRK-NKA
Posts: 192
Registered: ‎06-17-2008
0

Re: Load Balancing with SSG-140

Do you use BGP and your own IP adresses ?

Then you could perhaps use BGP to decide on IP level what goes were.

 

Else divide services up per ISP.

 

 


Best Regards

Tom Roholm
JNCIS-ENT, FWV, SEC, SA, WLAN
Distinguished Expert
echidov
Posts: 858
Registered: ‎11-02-2009
0

Re: Load Balancing with SSG-140

Hi,

 

You should also enable Equal Cost Multipath for this to work:

 

set vrouter <name> max-ecmp-routes 2 (up to 4 routes with the same pref/metric are supported).

 

I do not recommend to use ECM on the NATted connections, because:

 

"When ECMP is enabled and the outgoing interfaces are different and in NAT mode (apparently they mean not the interface mode but NAT as such. EC) , applications, such as HTTP, that create multiple sessions will not work correctly. Applications, such as telnet or SSH, that create one session should work correctly." (C&E, Routing)

 

Also:

"If the outgoing interfaces do not belong to the same zone and the return packet goes to a zone other than the intended one, a session match cannot occur and the traffic may not go through." (C&E, Routing)

 

I would recommend to use both connections as an Active/Standby with some load sharing using SBR (is simpler) and/or PBR.

 

Kind regards,

Edouard

Kind regards,
Edouard
Visitor
lm_gm
Posts: 1
Registered: ‎06-03-2011
0

Re: Load Balancing with SSG-140

Is this is supported in a HA configuration of two SSG 140?

Distinguished Expert
echidov
Posts: 858
Registered: ‎11-02-2009
0

Re: Load Balancing with SSG-140

Hi,

 

ECM/SBR/PBR will work the same way on a NSRP-cluster.

Kind regards,
Edouard
Contributor
TRK-NKA
Posts: 192
Registered: ‎06-17-2008
0

Re: Load Balancing with SSG-140

It is the same, unless you are talking active/active, that requires a different design approach.

 

 


Best Regards

Tom Roholm
JNCIS-ENT, FWV, SEC, SA, WLAN
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.