I need to get a fully redundant network setup. We have 2 cisco 1841's and 2 L3 switches (i dont know the model off the top of my head). We also have 2 different ISP connections and 2 different WAN IP addresses. This network is going to be used to host several servers that remote offices will connect to through VPN tunnels. It will also have some users connecting through RDP connections, and hosting exchange.
Right now we have 1 ISP going to each router, then each router goes to one of the switches. The switches have 2 vlans on them, one for a SAN network that is independent of everything else, and the other for all the network traffic. The switches are connected by two LAG ports and allow the network vlan traffic. Setup GLBP on the routers to provide a redundant gateway. My idea going forward was to setup OSPF on the routers and use VTI's for the VPN tunnels. I would also need to configure OSPF on the remote routers, but then i would be able to acheive redundant VPN tunnels.
Here is my issue:
First i had configured GLBP using a weighted load-balancing method. I soon noticed that my RDP sessions would quickly timeout and not reconnect. I would have to use the other external IP address to get back in. Again, that would only stay connected for a short time before kicking me off and making me switch ip addresses. I assumed that the ARP cache on the servers was timing out and sending another ARP request witch was returning a different virtual MAC address (in this case the other router) so the RDP session was being sent to the other router.
I decided to swithc the load-balancing method to host dependent. This allowed my RDP sessions to stay connected, but i could only connect using one of the external IP address. I would imagine thats because when the incoming packets come in on the "wrong" router, the server sends its RDP replys to its gateway (or active forwarder), and that active forwarder is a different router then the packets came in on. So one of the external IP's allows RDP's to some servers, and the other allows RDP's to the other server.
Is there a way to get things setup so traffic can come in on ether router (ether external IP address), and that traffic can find its way back out the ISP it came from (if nessicary like with a RDP session)? I used GLBP over HSRP and VRRP because i was hoping it would allow this traffic in on ether ISP, I didnt even thing that session traffic would still not work because it might get sent back out the wrong router.
Community Live- Basic Wireshark for Networking Students
(Live event - formerly known as Webcast- Tuesday 14 April, 2020 at 10 am Pacific/ 1 pm Eastern / 7 pm Paris)
This event will have place on Tuesday 14th, April 2020 at 10hrs PDT
Cisco IOS-XE 17.2.1 – Catalyst Switching Updates
Cisco has announced the availability of the latest IOS-XE release - IOS-XE Amsterdam 17.2. This release IOS-XE 17.2 is the next Standard Maintenance Release after 17.1 which also has a sustaining lifetime o...
In this article, we are going to talk about Cisco Umbrella Initial Setup.- The continuity of IT is the basis of today’s business environment. Almost every single decision made by business is either based on an IT data or done using the IT platform. And so...
This event had place on Tuesday 24th, March 2020 at 10hrs PDT
Daniel Dib is a Senior Network Architect at Conscia. He works with creating scalable, modular, and highly available network designs that...
Cisco DNA Spaces is a single, scalable, reliable location platform that digitizes spaces by centralizing location services for both people and things.
With Cisco DNA Spaces See what’s happening at your properties, and benchmark your performan...