Routing - Cipafilter Documentation

Manual - Routing

The Cipafilter is a fully featured router capable of replacing the functionality of your existing routers.

Most customers will not need to reconfigure any features on this page, since the filter will automatically route between any subnets specified on the IP Settings page.  If it is necessary to route to any additional subnets, they can be added here by specifying the destination subnet itself and the gateway to route through.

Multi-Gateway Routing

Multi-gateway routing provides advanced routing functionality which is useful for organizations with multiple Internet connections or complex network set-ups.  These features provide several benefits, including load balancing and fail-over, as well as the ability to specify static routes based on the source rather than the destination (as with the Routing tab).

The Multi-Gateway Routing Mode indicates the type of routing to perform: Destination Based or Source Based.  In Destination Based mode, the filter will distribute requests amongst the specified gateways according to their destination (external) IPs; in Source Based mode, the requests will be distributed according to their source (internal) IPs.  The distribution is weighted according to the values specified, but is otherwise arbitrary.

Beneath the mode setting is the table of gateways and interfaces to use for routing.  The Gateway field indicates the default gateway for the associated Out-Interface.  The Watchdog Target specifies an IP address to watch for which indicates the availability of the gateway; if this target fails to respond, the filter will stop routing to the associated Gateway and fail over to one of the others.  The Weight field specifies the distribution weighting; in general, the higher the Weight value, the more traffic will be routed through that Gateway.

As an example: Two gateways (Gateway A and Gateway B) are specified with equal weights using the Source Based method.  Behind the filter are Clients A, B, C, and D. As each client passes a request through the filter, the client is "assigned" a route to one of these gateways.  All subsequent requests from the clients are then passed through their associated gateways.

Ideally, given equal weights, the clients will be equally distributed — e.g., Clients A and C to Gateway A and Clients B and D to Gateway B — although this is not guaranteed.  This functionality is referred to as load balancing.

If the Watchdog Target for Gateway B were to go down, the filter would then re-"assign" Clients B and D back to Gateway A to ensure connectivity.  The exact settings the filter uses to detect this scenario can be changed under Ping Watchdog Settings.  This functionality is called fail-over.

Multi-gateway routing currently does not integrate well with the filter's DHCP-client functionality, and using the two features together is not supported.  (DHCP-server functionality is unaffected.)

Ping Watchdog Settings

To ensure connectivity through a gateway, the filter must periodically ping its Watchdog Target.  The number and frequency of pings can be set here.

Specific Connection Routing

This section is the source-based equivalent to the destination-based routes specified on the Routing tab.


    • Related Articles

    • Manual

      This article provides links to the individual sections of the Cipafilter product manual.  A PDF of the Cipafilter product manual is attached to this article. Introduction Interface Conventions Installation Status Management Users Hot Spare ...
    • Manual - Introduction

      Cipafilter is a powerful routing platform capable of delivering an evolving tool set to protect your enterprise. Cipafilter's philosophy is to provide a cuing edge, well rounded, and aggressive network control solution to meet your current and future ...
    • Manual - Web Filtering

      The first thing to decide with regard to Web filtering is whether to run individual subnets in transparent or non-transparent (proxy server) mode. Transparent mode  — no client configuration is required, the Cipafilter simply intercepts all traffic ...
    • Manual - Network Diagnostics

      The Network Diagnostics page serves as a basic front-end for common network troubleshooting utilities such as ping and traceroute.  These utilities can be used to confirm the filter's Internet connectivity and network configuration: The automatic ...
    • Manual - Installation

      In most cases you will want to consult with Cipafilter support to decide what way the router can best be installed to meet your needs.  A full over-the-phone consultation during installation is included in the standard one-year maintenance and ...