Hi all,
Is anyone experiencing any problems with ISP redundancy when upgrading from R77.30 to R80.20?
Basically what is happening is that the client has a firewall with ISP Redundancy Active/Backup. The Active connection is the PPPoE while the Backup connection is the fiber link with a /28 subnet. Now, with R77.30, with this configuration, traffic goes out through the PPPoE connection. Services which are NATted on the Fiber (backup link) still work. If you do an FWmonitor, you can see that a request to a web server on the backup link, hits the correct NAT rule, reaches the server, the server replies back, NATs and goes out of the backup link interface. So far so good.
From R80.20, if you try the same procedure, you can see that the request comes from the backup link, BUT reply goes out of the primary link, causing asymmetric routing.
To be honest this used to happen on R77.30 but if you disable secureXL issue would be sorted.
This is a huge issue since R77.30 is reaching end of life and all clients should be migrated to r80.XX or later.
Anyone experiencing anything similar on his setup?
Thanks
Darryl.
Senior Information Security Engineer