We're starting to implement more Layer 2 connections from Cable Providers for high speed WAN links.  The prices of these links are very reasonable compared to MPLS and Frame Relay.  However it's very important to properly throttle and match the same speed on the firewall as the Layer 2 connection.  We typically connect the Layer 2 connection to a separate interface on the firewall so we can control the traffic between the LAN and WAN and prevent unnecessary traffic on the WAN link.

For example if you’ve purchased a 50mb/sec Layer 2 WAN link between two sites the Cable provider will typically provide a 100mb/sec Ethernet connection at each site.  If you don’t properly throttle the WAN link on the firewall it will try to push 100mb/sec across the Layer 2 network.  Since the Layer 2 connection can only handle 50mb/sec you will drop packets on the WAN link.  In a worse case scenario, we’ve seen the firewall/router hang or the interface on the firewall randomaly disconnect without any entries in the firewall logs.
To limit the bandwidth on a Sonicwall NSA 2400 complete the following steps:
  1. Login to the Sonicwall NSA 2400 with a Web Browser.
  2. Click on Firewall Settings.
  3. Click on BWM ( Bandwidth Management).
  4. Set the Bandwidth Management Type to Global.
  5. Click on Network and edit the interface of the Layer 2 WAN link.
  6. Click on the Advanced Tab.
  7. Check the Enable Egress Bandwidth Management checkbox and set it to the speed of the Layer 2 WAN speed.  For example if the connection is 50mb/sec you would enter 50000.
  8. Check the Enable Ingress Bandwidth Management checkbox and set it to the speed of the Layer 2 WAN speed.  For example if the connection is 50mb/sec you would enter 50000.
  9. Click Ok.

Hopefully this post may prevent a lot of grief when utilizing these types of WAN links.4/5/2013

Firewall

Get updated on the latest Information Technology news, Cybersecurity, Information Technology Trends, and recent real-world troubleshooting experiences.

SUBSCRIBE NOW!