SmoothWall.net home page Evaluate SmoothWall
» Company Information » Testimonials » Case Studies » Press, Reviews & PR » Key Staff Biographies » News Archive » Events » Jobs
» Cyberbullying – A guide for ICT staff in Schools » Secure Wireless » Anonymous Proxies » Load Balancing » Blocking Ultrasurf and HTTPS proxies
- Firewall & VPN - » Advanced Firewall 2008 » Corporate Firewall 2008 » School Guardian 2008 » VPN and Secure Remote Access » Express - Web Security & Content Filtering - » Network Guardian 2008 » School Guardian 2008 » SmoothGuardian - Email Security - » SmoothZap 2008 - Bandwidth Management (QoS) - » SmoothTraffic 2008 - Appliances - » SmoothGuard 1000-UTM - Our Full Product List - » Brochures & Datasheets » Feature Comparison Chart » How to Buy
» Reseller List » Become a Partner » PartnerNet this is a link to external content
» Support from SmoothWall » Support from SmoothWall Partners » Supported Products » FAQ & Knowledge Base » Submit a Support Ticket » Manuals » Downloads » Training » Hardware Compatibility Guide » Product Updates » Blocklist Addition/Removal » Password Generator » Glossary » Terms & Conditions
» SmoothWall.org » Version 3 Sources » Version 4 Sources » Version 5 Sources » Version 2008 Sources
» Addresses and Phone Numbers » Sales/Pre-Sales Enquiry » PR Contacts » Account/Invoice Enquiries » Submit a Support Ticket
CompanySolutionsProductsPartnersSupportCommunityContact Us
home »
Load balancing and the efficient use of multiple Internet connections

One of Advanced Firewall major strengths is its ability to support multiple simultaneous Internet connections with load balancing of both incoming and outgoing traffic.

Load Balancing (Outgoing Traffic): Utilizing multiple Internet connections can offer reliability, performance and provisioning cost benefits.

Automatic re-routing of traffic from a failed connection to other alternative connections avoids the risk of a single failure cutting everybody off from the Internet. A DSL connection can be used to backup a leased line such as a T1, or DSL connections could be taken from different ISPs with their own local distribution networks to avoid a single point of failure. There is no need for unused standby connections, all connections can be utilized during normal operation.

Distributing traffic across multiple connections on the basis of protocol can be used to separate low volume and interactive traffic from heavy background traffic. A typical example might be routing web browsing and Voice over IP telephony via one connection with file transfers and email using another. This will improve the performance of these interactive services as they will experience far less bandwidth contention. Alternatively traffic can be routed on the basis of its source, with traffic from particular user groups or servers being routed via connections with more available bandwidth. Protocol and source rules can be combined if necessary.

Individual IPSec VPN tunnels can be configured to use any of the available network connections.

Adding another Internet connection can be less expensive and less disruptive than upgrading one already in use. It may also not be possible to obtain a single higher bandwidth connection at an affordable price, with two or more slower connections being much more economical.

Load Balancing (Incoming Traffic): To protect against the risk of a single Internet connection failure causing systems to become unreachable from the Internet, Advanced Firewall can route traffic from multiple Internet connections to a single server in a DMZ. This is achieved by first configuring the DNS entries for the server to use two or more public IP addresses which are presented or separate Internet connections, preferably from different ISPs with their own distribution network. Advanced Firewall is then configured with Port Forward rules to route traffic from these Internet connections to the actual server providing the service. Clients accessing the server will be allocated any one of the available IP addresses by DNS, so traffic will utilize all the Internet connections that have been configured in DNS. However, in the event of one of these Internet connections failing, clients attempting to use the failed connection will be automatically allocated one of the alternate (working) IP addresses by DNS. Advanced Firewall provides a connection failure resilient environment for the hosting of web, email and other Internet servers.

Load Balancing (To Multiple Servers): Advanced Firewall can distribute traffic between multiple servers in a DMZ that are all performing the same task using Round Robin load balancing.
Network Guardian 2008

NECC 2008, San Antonio, Texas, USA


Web Security and Content Filtering Bandwidth Management (QoS) Firewall & VPN