ISP Redundancy failover, impact to outbound non FW hosts Is it possible for sessions initiated outbound to use the NAT associated with the remaining ISP interface that is not assigned to the firewall object? I have SPLAT NGX 61 running with 2 ISP connections. Currently it is defined in Primary/Backup. The Email server has an IP address associated with each interface. I use manual address translation for incoming packets for each interface, 2 statement. Outgoing I also have manual address translation for each interface, 2 statements. I have defined a host route from each routable address to this host and have manually added an ARP entry for each external host address. When both links are up every this works fine. I can shift to load sharing and both interfaces are used properly. When I take the primary down the packets are still being translated using the primary static NAT so the packets are not routable through that interface. If I use the “hid behind the gateway”, this is a different IP address than the host uses so conversations are not being handled over the same IP address. |