Connect. Communicate. Collaborate. Securely.

Home » Kerio User Forums » Kerio Control » Load Balancing Issue (Problem Using 2 Different Interface with one of them using Proxy Server Authentification)
  •  
vino

Messages: 2
Karma: 0
Send a private message to this user
To all Kerio Experts,

I had been facing an issue within this few days, the problem is i tried to use two different Internet Interface and i could not figured out to make it happen, especially because that one of that internet interface is using a proxy server authentication.

This is the scheme:

1. Internet Interface #1: DHCP IP Address and Using a proxy server authentication at 10.1.1.16 Port:80
2. Internet Interface #2: DHCP IP Address and direct access (No problem with this one)

The problem is if I tried configured it by forwarding all the traffic to parent poxy server at 10.1.1.16 Port:80, the Inet Interface #2 will be useless.

I also already tried to use "Enable Destination Nat to 10.1.1.16 Port:80 " from the traffic rules customized only to use specific interface (Inet Interface #1), but it is not working.

Can any of you guys help me with this, maybe by giving me an example of Traffic Rules for my condition above.

[Updated on: Sun, 01 September 2013 10:17]

  •  
silars

Messages: 429
Karma: 59
Send a private message to this user
That proxy server looks to be a problem.

You can probably get a rule to work, but you won't have any load-balancing or failover. The issue is that failover is done by interface. The rule would still try to forward to a proxy server on Interface #2 (which doesn't exist).

Best case would be you get some users on Interface #1 and some on Interface #2. But, they won't be able to use the other interface in case of failure.

Is this what you want?
  •  
vino

Messages: 2
Karma: 0
Send a private message to this user
The scenario i would like to have is that for the most website address (almost all) all the users will use Inet Interface #1 (the one that have proxy server authentication) and for several website address (about 40-50 site addressees) all users will use this Inet Interface #2.

So that for some selected website addresses all users will be directed to use Inet Interface #2 but for the most website addresses all of the users will use Inet Interface #1

Is there any traffic rule example you can show me for this to work ?

Note: the proxy server authentication on Inet Interface #1 is at 10.1.1.16 port:80


  •  
silars

Messages: 429
Karma: 59
Send a private message to this user
If the proxy server requires authentication, I don't know if this is possible.

The idea of Destination NAT would be my first place to go, but you say that isn't working. That leads me to believe it has authentication. Since there doesn't appear to be a manner in which to define an outgoing rule to use a proxy service, it would appear this is a dead end.

At this point, you may need to contact Kerio Support directly (this is a user-user forum), or your reseller.

You could ask the proxy server to not require authentication and retry your Dest NAT rule.
Previous Topic: Kerio as a Gateway
Next Topic: Internal resources publishing
Goto Forum:
  


Disclaimer:
Kerio discussion forums are intended for open communication between forum members and may contain information and material posted by members which may be useful in learning about Kerio products. The discussion forums are not intended to provide technical support for any specific product. Any information implied or expressed in the discussion forums is that of the posting member. Kerio is in no way responsible for the information posted in the forums, or its accuracy. Kerio employees may participate in the discussions, but their postings do not represent an offical position of the company on any issues raised or discussed. Kerio reserves the right to monitor and maintain the forums to promote free and accurate exchange of information.

Current Time: Sun Sep 24 23:21:48 CEST 2017

Total time taken to generate the page: 0.00429 seconds
.:: Contact :: Home ::.
Powered by: FUDforum 3.0.4.