Load Balancing Failure

Fajri Rohmana Lv1Posted Jun-05-2025 18:20

facing an issue with the load balancing configuration on our Sangfor NGAF device involving two internet connections:

ISP 1 (Primary): Static Public IP assigned on Interface ETH2

ISP 2 (Secondary): Dynamic IP via DHCP on Interface ETH4

Interface ETH3: Used for Metro Link connection to another site

Steps Already Taken:

Added the WAN interfaces as follows:

ETH2 configured with Static Public IP for primary internet

ETH4 configured with DHCP for secondary internet

Configured Policy-Based Routing (PBR) using Prefer Link at Top option:

Primary Link: ETH2

Secondary Link: ETH4

Created Static Routes to 0.0.0.0/0 via each interface’s respective gateway (ETH2 and ETH3)

For ETH4 (DHCP), the Obtain default route option was unchecked

Current Issue:

After applying the configuration, ETH2 (the main link) becomes inactive, and internet connectivity is lost

Internet access is only restored after manually disabling ETH4

Load balancing does not work as expected and seems to cause connectivity failure

Zonger has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Last edited by Zonger Jun-12-2025 03:23.

Based on your configuration and symptoms the issue stems from conflicting default routes and improper PBR implementation.

Route Priority Conflict: Both ETH2 and ETH4 had active default routes. The DHCP route intermittently took precedence causing ETH2 to appear "inactive."

Health Check Missing: Without monitoring PBR couldn't detect ETH2's status leading to erratic failover.

Kindly follow below resolution steps:

1. Delete the static default route for ETH4 (DHCP) and only keep one default route via ETH2's gateway.
3. Adjust PBR for Failover.
4. Disable DHCP Default Route on ETH4.
5. Verify Metro Link Configuration.
Is this answer helpful?
Faizan Khan Lv1Posted Jul-11-2025 13:18
  
Thanks for this information.
mantasha Lv2Posted Jun-08-2025 17:59
  
Hello, could you please show your setups for better comprehension?  particularly the PBR configuration
Ayra Posted Jun-08-2025 17:56
  
Hello, Fajri  Even with DHCP unchecked, it appears that ETH2 may be being overwritten by a default route from ETH4.  To be sure, look at the routing table.  To guarantee preference, set a higher metric for ETH4 and a lower one for ETH2.  Additionally, make sure ETH2 isn't being marked down by the health check.  To see if ETH2 is stable, try temporarily removing ETH4.
AimanHakim Lv2Posted Jun-06-2025 23:54
  
Hi, can u show ur configurations for better understandings. especially the PBR config
Sengor Lv1Posted Jun-06-2025 23:34
  
Hey Fajri, it looks like ETH2 might be getting overridden by a default route from ETH4, even with DHCP unchecked. Check the routing table to confirm. Set a lower metric for ETH2 and a higher one for ETH4 to ensure preference. Also, verify ETH2’s health check isn’t marking it down. Try removing ETH4 temporarily to see if ETH2 stays stable.

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

917
183
94

Started Topics

Followers

Follow

Board Leaders