ScreenOS Firewalls (NOT SRX)
Highlighted
ScreenOS Firewalls (NOT SRX)

SSG-140 PBR reverse web proxy failover?

[ Edited ]
‎07-11-2017 05:11 PM

We currently use an SSG-140 firewall in front of our servers and I am interested in setting up a reverse web proxy. I know I can do that using policy based routing and directing the traffic to a proxy server like squid. What I haven't been able to find in my searching is if there is a way for the firewall to detect if the proxy server is offline and when it is direct the traffic directly to the origin web server. Does anyone know if there is a way to do this in ScreenOS? I'm using ScreenOS 6.3.0r12.0

3 REPLIES 3
Highlighted
ScreenOS Firewalls (NOT SRX)

Re: SSG-140 PBR reverse web proxy failover?

‎07-11-2017 07:44 PM

PBR is marked down automatically if the next hop is not reachable or the exit interface can be brought down using the track-ip. There is no tracking for the PBR for a specific destination.

 

Thanks,

Vikas

Highlighted
ScreenOS Firewalls (NOT SRX)

Re: SSG-140 PBR reverse web proxy failover?

‎07-13-2017 10:01 AM

So if the proxy server was totally down or the ethernet link was down the PBR would be ignored? But if the squid proxy software just wasn't responding, the PBR would still be in effect and the traffic would basically be blackholed? Does that sound accurate?

Highlighted
ScreenOS Firewalls (NOT SRX)

Re: SSG-140 PBR reverse web proxy failover?

‎07-13-2017 05:26 PM

That is correct, the only track option available is ping not a service.

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Feedback