
Creating Custom Rules for the Outbound Policy
63
BODi rS BD1000 User Manual
5 • Managing Outbound Traffic to the WAN
Algorithm: Weighted Balance
The Weighted Balance Algorithm specifies the ratio of WAN connection usage to be applied on the specified
IP Protocol and Port. These settings only apply when the Algorithm is set to
Weighted Balance
(shown in
The amount of matching traffic that is distributed to a WAN connection is proportional to the weight of the
WAN connection relative to the total weight. Use the sliders to change the weight for each WAN.
For example, the weight settings in the bulleted list have these results:
•
WAN1:
10
•
WAN2:
10
•
WAN3:
5
The total weight is 25 = (10 + 10 + 5)
Matching traffic distributed to WAN1 is 40% = (10 / 25) x 100%
Matching traffic distributed to WAN2 is 40% = (10 / 25) x 100%
Matching traffic distributed to WAN3 is 20% = (5 / 25) x 100%
Algorithm: Persistence
The Persistence Algorithm provides solutions to fix undesirable link load distribution for Internet services.
For example, many e-banking and other secure websites, for security reasons, terminate the session when the
client computer’s Internet IP address changes during the session.
In general, different Internet IP addresses represent different computers. The security concern is that an IP
address change during a session may be the result of an unauthorized intrusion attempt. Therefore, to prevent
damages from the potential intrusion, the session is terminated upon the detection of an IP address change.
The BD1000 can be configured to distribute data traffic across multiple WAN connections. Also, the Internet
IP depends on the WAN connections where communication actually takes place. As a result, a LAN client
computer behind the BD1000 may communicate using multiple Internet IP addresses. For example, a LAN
client computer behind an BD1000 with three WAN connections may communicate on the Internet using
three different IP addresses.
When using the
Persistence
Algorithm with the BD1000 (
on page 64), rules can be configured to
enable client computers to persistently utilize the same WAN connections for e-banking and other secure web-
sites. As a result, a client computer will communicate with the other end using one IP address to eliminate the
issues.