<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic load-sharing versus firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/load-sharing-versus-firewall/m-p/703086#M1034058</link>
    <description>&lt;P&gt;I have a 2811 with two T1 lines incoming which are set to load-sharing per-packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to be able to send traffic out (web browsing, IM, etc.) and allow traffic in to specific servers (http, https, etc.).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been tearing my hair out trying to get the firewalling to work correctly. It appears that the firewall (in particular inspecting outgoing traffic) is not compatible with load-sharing per-packet. I end up with packets dropping (which suspiciously turns out to be about 50% of them).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have experience getting this to work or have ideas for things to try?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm at the point where I'm just going to put another firewall appliance behind the 2811 and call it a day. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;      Greg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 08:59:29 GMT</pubDate>
    <dc:creator>ggilley</dc:creator>
    <dc:date>2019-03-11T08:59:29Z</dc:date>
    <item>
      <title>load-sharing versus firewall</title>
      <link>https://community.cisco.com/t5/network-security/load-sharing-versus-firewall/m-p/703086#M1034058</link>
      <description>&lt;P&gt;I have a 2811 with two T1 lines incoming which are set to load-sharing per-packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to be able to send traffic out (web browsing, IM, etc.) and allow traffic in to specific servers (http, https, etc.).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been tearing my hair out trying to get the firewalling to work correctly. It appears that the firewall (in particular inspecting outgoing traffic) is not compatible with load-sharing per-packet. I end up with packets dropping (which suspiciously turns out to be about 50% of them).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have experience getting this to work or have ideas for things to try?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm at the point where I'm just going to put another firewall appliance behind the 2811 and call it a day. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;      Greg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-sharing-versus-firewall/m-p/703086#M1034058</guid>
      <dc:creator>ggilley</dc:creator>
      <dc:date>2019-03-11T08:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: load-sharing versus firewall</title>
      <link>https://community.cisco.com/t5/network-security/load-sharing-versus-firewall/m-p/703087#M1034059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Greg.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please give some details as to where the firewall is placed in your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 11:07:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-sharing-versus-firewall/m-p/703087#M1034059</guid>
      <dc:creator>zubairjalal</dc:creator>
      <dc:date>2006-11-23T11:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: load-sharing versus firewall</title>
      <link>https://community.cisco.com/t5/network-security/load-sharing-versus-firewall/m-p/703088#M1034060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically, the two T1s are my WAN connections. I have load-sharing per-packet on them to boost performance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Behind the 2811 is my LAN connection. On it I have various servers. I also have a connection to another router which has clients behind it. So I need to allow traffic to my servers on my LAN and traffic out from the LAN from the other router to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the basic config. I've left the rules out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 12.xx.xx.xx 255.255.255.240&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; no mop enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Serial0/0/0&lt;/P&gt;&lt;P&gt; bandwidth 1536&lt;/P&gt;&lt;P&gt; ip address xx.xxx.xxx.xxx 255.255.255.252&lt;/P&gt;&lt;P&gt; ip verify unicast reverse-path&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-packet&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; service-module t1 remote-alarm-enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Serial0/1/0&lt;/P&gt;&lt;P&gt; bandwidth 1536&lt;/P&gt;&lt;P&gt; ip address xx.xxx.xxx.xxx 255.255.255.252&lt;/P&gt;&lt;P&gt; ip verify unicast reverse-path&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-packet&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; service-module t1 remote-alarm-enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 17:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/load-sharing-versus-firewall/m-p/703088#M1034060</guid>
      <dc:creator>ggilley</dc:creator>
      <dc:date>2006-11-23T17:22:31Z</dc:date>
    </item>
  </channel>
</rss>

