Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Cluster ISA over WAN

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 General] >> Installation and Planning >> Cluster ISA over WAN Page: [1]
Login
Message << Older Topic   Newer Topic >>
Cluster ISA over WAN - 22.Oct.2008 9:20:04 AM   
johnisccp

 

Posts: 6
Joined: 29.Sep.2008
Status: offline
I would like to setup a ISA 2006 cluster over the WAN if possible.  I am setting up an Exchange 2007 CCR Cluster over WAN.  Two Datacenter in different location.  This is what I would like to happen.  If primary ISA server fail, it will fail over to the standby ISA at the other Datacenter location.  Has anyone done this or know how?

Thanks in advance. 
Post #: 1
RE: Cluster ISA over WAN - 22.Oct.2008 3:35:02 PM   
mascalia

 

Posts: 36
Joined: 13.Feb.2008
Status: offline
I'm pretty sure you can't do what you want with only two ISA servers (or two ISA arrays) seperated by WAN links.  A couple of thoughts come to mind.

First, ISA clustering is based on Microsoft Network Load Balancing (NLB) which doesn't work across a WAN.  In fact, best practices for NLB are to have the NLB network adapters in a separate VLAN (or switch).  There are many other reasons, but NLB across a WAN link isn't an option, so ISA clustering isn't an option.

Second, you didn't state if only the ISA servers would be in different data centers with your app servers in a central site (redundant links), or if you will have redundant app servers as well (a DR site, complete with backup ISA server and app servers).  Not sure what Exchange CCR is; does it allow building a fail-over Exchange cluster over WAN links?

Regardless, though, if you have redundant links via separate ISA servers, you have to have a mechanism outside the two ISA servers to (a) detect the failed primary link and (b) redirect traffic to the backup link.  There are many, many different ways to do this;  routers can do it, front-end loadbalancer applicances can do it, firewalls can do it, even ISA can do it.  Regardless, though, you'll need something else besides your two primary ISA servers to fill this role.

As an example, in our company we have a corporate load-balancing soution from F5 that performs two functions:  it load-balances between the primary and backup data centers (for solutions that support such load-balancing), and also performs link/route redirection from the primary to backup link for solutions that don't support WAN load-balancing (such as webapp servers, etc...).  At the two data centers, we will be installing ISA arrays. 

Traffic from the 'net will come through the F5 solution, and get sent to the primary array.  In the event of a link failure, the F5 solution will redirect traffic to the backup array at the backup data center.  There's more to it than that, but the gist is that we needed something else in front of the two ISA arrays to detect failed links and redirect traffic.  Unless I misunderstood your need, I think you're in the same boat, mate.

Hope this helps.  And if you find something different (or if I'm wrong), please come back and let me know.

Mike

quote:

ORIGINAL: johnisccp

I would like to setup a ISA 2006 cluster over the WAN if possible.  I am setting up an Exchange 2007 CCR Cluster over WAN.  Two Datacenter in different location.  This is what I would like to happen.  If primary ISA server fail, it will fail over to the standby ISA at the other Datacenter location.  Has anyone done this or know how?

Thanks in advance. 


< Message edited by mascalia -- 22.Oct.2008 3:36:48 PM >

(in reply to johnisccp)
Post #: 2
RE: Cluster ISA over WAN - 22.Oct.2008 7:37:10 PM   
Jason Jones

 

Posts: 2256
Joined: 30.Jul.2002
From: United Kingdom
Status: online
I would concur with Mike and two data centres normally means two ISA Server arrays, one at each location. You then use integrated NLB to provide array member fault tolerance at each data centre. I would also agree that you need something clever in front of ISA to ensure that the traffic reaches the correct ISA array based to provide true site redundancy.

NLB is 'subnet bound' hence you cannot use NLB across a routed link, which is what you mean by WAN I asssume?

I have had some customers use stretched VLANs across physcial sites and therefore be able to stretch a signle array across two physcial sites. However, you need subnets to be presented/stretched across both sites so that ISA interfaces in all array members exist in the same subnets as each other. This is possible with the right connectivity and network configuration. As long as all ISA array members have each interface set in the same subnets, ISA should be happy.

Cheers

JJ 

< Message edited by Jason Jones -- 22.Oct.2008 7:38:23 PM >


_____________________________

Jason Jones (MVP)

Silversands Limited http://www.silversands.co.uk
My Blog: http://blog.msfirewall.org.uk/

Get our NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to mascalia)
Post #: 3

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 General] >> Installation and Planning >> Cluster ISA over WAN Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts