A
A
Alex Leggecom2020-01-29 08:22:47
Computer networks
Alex Leggecom, 2020-01-29 08:22:47

Failover remote access, is it possible under the following conditions?

Given:
Server with remote access;
Mikrotik with configured redundancy;
Communication channel with white IP from ISP 1;
Communication channel with white IP from ISP 2;
Question:
Is it enough to register a route between IP addresses on WAN interfaces so that, with a downlink from ISP 1, a remote user can connect to the server requesting access via a leased IP from ISP 1 through a link from ISP 2 and vice versa ???

Answer the question

In order to leave comments, you need to log in

4 answer(s)
D
Dmitry Shitskov, 2020-01-29
@Zarom

No, this scheme will not provide fault tolerance for ip if it was rented from one of the providers.
To ensure the fault tolerance of an external address, the following conditions must be met:

  • IP belongs to your organization
  • AS is registered to your organization
  • With each provider you have bgp peering and you announce your ip-address to the providers

A
Andrey Barbolin, 2020-01-29
@dronmaxman

Maybe. It is very difficult to buy AS now, and there is no such need if you have 3 servers.
You can rent a VPS and set up 2 VPN tunnels on it to Mikrotik through each of the providers.
Publish ports on VPS, and configure route switching when any of the providers fails. For example, run OSPF.
The scheme is quite working, they implemented this at several offices. It is especially true if the provider gives you a gray IP (for example, a mobile operator).

I
iddqda, 2020-01-29
@iddqda

if only isp1 and isp2 get married and give birth to a non-standard solution in your favor
, and so hang up two local ip on your server and on Mikrotik forward the port from each external to each internal address
for convenience, you can change the service address in the DNS dynamically if any ISP is unavailable

C
CityCat4, 2020-01-29
@CityCat4

Fault tolerance is provided not by the number of channels, but by the transmission to the world of information that now such and such addresses are available through such and such. Timely transmission. As a rule, for this, ASs are bought / rented and configured with each of the BGP providers. And then each provider will transfer this information further along the chain to all other providers.
Without such a trick with the ears, a fail-safe connection can only be provided for the local network, it is impossible to connect external services in this way.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question