Reply
New Member
Posts: 7
Registered: ‎03-04-2016
Kudos: 1
Solutions: 1

EdgeRouter VRRP Failover and NAT Tables

Hi there,

 

I'm looking at putting a pair of EdgeRouter 8s in my office as Internet-facing firewalls, and using VRRP for failover / redundancy. I have a couple of questions:

 

  • How quickly can I expect failover to occur if one device unexpectedly dies?
  • These routers will also be doing IPv4 NAT for the local network to the Internet; do they share NAT tables or will TCP connections fail when the routers fail over?

My other option is to go for a full pacemaker / conntrackd stack on Linux boxes, but if I can save myself the hassle I will!

 

Cheers,

Dave

Senior Member
Posts: 4,133
Registered: ‎01-04-2017
Kudos: 564
Solutions: 197

Re: EdgeRouter VRRP Failover and NAT Tables

1. Depends how fat a part the hello timer is set.
2. TCP connections will fail, conntrack is not sync'd.
Senior Member
Posts: 4,133
Registered: ‎01-04-2017
Kudos: 564
Solutions: 197

Re: EdgeRouter VRRP Failover and NAT Tables

[ Edited ]

If you search the forums you may find a third party package to sync conntrack.

 

https://community.ubnt.com/t5/EdgeRouter/VRRP-statefull-failover/m-p/485849#M9948

Reply