Automatic IP switching when internet connection is lost.


Recommended Posts

Hi All.

We are looking at setting up a system where if our main connection to the internet is lost, router fails, line faults etc then our network would automatically switch to a second backup line. The data it would need to change is the gateway and DNS servers as all PWAN traffic uses internal IP addresses to access company websites (intranet, accounts and management tools). If we switched over to the backup line then we would like it to use the public IP address.

What I am looking for is something like this.

Normal details

IP range 192.168.11.0

Gateway 192..168.11.250

DNS 192.168.11.1

In the event that an internet connection is not available

Switch too

Gateway 192.168.11.254

DNS 192.168.11.10

If there is an automatic solution that uses a trigger of some sort then perfect as I would prefer it to not need an administrators input (we do sometimes need to travel to other sites plus one of our offices works shifts) but at this time I am open to all suggestions.

You would not switch the clients, you would just run HA routers with multiple wan connections. What routers do you use now?

So if running say pfsense, this is how you would do it

http://doc.pfsense.o...ancy_%28CARP%29

Your not going to want to change clients to different dns and gateway -- and I don't know of a automated way of doing that if you did.. What you could do as simple manual way would be to change your dhcp scope, and then have users either renew the dhcp lease to get the new info or reboot.

But a better solution would be to setup HA on your routers so the IP never changes.. With different internet connections you now get hardware redundancy along with connection - and you could even load balance your connections across both your internet connections in this sort of setup.

edit: Curious what sort of location is this? Guessing not a Windows AD environment if your pointing directly at the routers for dns? Oh wait your dns is not your gateway IP. Why would you need to change the dns if the gateway failed?

We use the Cisco RV082 now for this, the RV016 is also an option if you have more than 2 WANs.

Not saying these are the only options, just that they work well for us in that it auto switches when in backup mode (1 is used as main and the other is backup) or balance the load over both networks automatically using only 1 if 1 goes down.

^ but I think he mentioned if the router went down as well, not just the internet connection. I was not aware that the RV line could do HA with another RV router? if so - then yeah that would be a low priced solution.

OOps, yeah, guess I missed that last part.

If you set multiple gateways in a DHCP scope would it confuse the clients or would they just use the first on the list till it's not available (sorta like DNS servers)?

We are currently using Cisco 1921 routers that are managed by the ISP. We have 2 lines that were going to be bonded but issues with one of the lines brought both down meaning in this case the router was active and the line was showing as connected but there was no activity being past on either line. We have also had a instance when another Cisco 1921 was potentially the issue but ideally we are looking for a solution that covers both line connection issues and hardware failure. We also have a second ADSL line which I would like to use as the backup and the line the server use to upload our backups to (which I currently do with a persistent route) which is managed by a Draytek 2930 router.

If I use multiple gateways wouldn't the client always use the primary until the router wasn't available regardless of line status? Also how can I switch DNS? When the users are connected via the primary line they use private IP's which are set in our DNS servers, the backup will breakout to the internet with no link to the datacentre so they would need to switch to using public IP's. I have spoken to the provider about this as I wanted to remove all manually added zones from our DNS server and just leave the AD integrated zones.

The initial requirement is to use an automated system where the switchover is taken care of with no user input, should a fault happen out of normal business hours when it is only the night people working then the time it would take us to manually switch them could cost us financially. However as a back up to the backup, I would also like a way for them to easily switch themselves over should the automated system fail.

Going to take a look at pfsense, budman. I know you have recommended it several times before.

I am fairly sure a 1921 can do HSRP.. how you would tie in your dual internet connections not sure.

But still thinking about it the wrong way.. You don't change your lan IP scope just because your internet connection changes, or the hardware to the connection fails.

You setup a ha pair with hsrp or virtual IP, lots of different terms for pretty much the same thing. You have 2 routers, and then either 1 or more internet connections on the wan side connected to these routers. You then route traffic to the connection you want, be it using 1 and other as fallback, or load balancing, etc. from the lan side nothing changes if one of the routers fail. Since the router that is currently active will hold that gateway IP your clients use.

And I still at a loss to why you should have to change your dns if your internet connection changes? Your local dns would still work, or use a non isp based external dns, etc.

  • 2 months later...

I am fairly sure a 1921 can do HSRP.. how you would tie in your dual internet connections not sure.

But still thinking about it the wrong way.. You don't change your lan IP scope just because your internet connection changes, or the hardware to the connection fails.

You setup a ha pair with hsrp or virtual IP, lots of different terms for pretty much the same thing. You have 2 routers, and then either 1 or more internet connections on the wan side connected to these routers. You then route traffic to the connection you want, be it using 1 and other as fallback, or load balancing, etc. from the lan side nothing changes if one of the routers fail. Since the router that is currently active will hold that gateway IP your clients use.

And I still at a loss to why you should have to change your dns if your internet connection changes? Your local dns would still work, or use a non isp based external dns, etc.

As the norm budman is correct :) 1921s do HRSP. You require a 1921 for each net conn and you pair them for Ha/hrsp. 3 LAN IPS are required. 1 for each 1921 and one for hrsp. I have a pair of fibre 100mb converted/presented as cat6 entering the premises main conn into first 1921 and backup fibre into 2nd 1921. The hrsp IP becomes your DG and the 1921s manage failover with out any connectivity loss to clients.

^ yup! I didn't got into the internet side of it because not very clear on what exact sort of connections you have or want to use, etc. Be it a board on your 1921, be it just plain jane ethernet connected to it, etc.

We can for sure get into details if you want, its just the whole idea of changing your whole lan IP space on a loss of internet, or switch to different one makes no sense at all.

Now if you want to discuss the DNS side if more - you mention AD.. So would assume you have some AD box doing your AD dns, this should be the ONLY dns for your AD members. This server would then forward all requests it is not authoritative to some other box.. Now if your forwarding to an ISP dns, it might not allow you to use that one if your not coming from their network.. Which is why you could have both internet connections isps dns setup, or your local dns could go directly too roots for stuff it doesn't know, or it could use one of the many other public dns out there that does not care what network you come from.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Same Internet Archive seemed to grab the new version https://web.archive.org/web/20...d/Setup_MakeMKV_v1.18.4.exe
    • Windows 11 KB5094126, KB5093998 bugging out Office apps but it may not be Microsoft's fault by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. Although the tech giant did not acknowledge any major problems, some users online reported various issues ranging from OneDrive and Dropbox access problems, BitLocker recovery lockouts, to blue screens and BSODs. You can read about them in this dedicated piece. While there is still no confirmation about those problems from Microsoft the company has admitted to another bug which we did not report on. The tech giant has confirmed it has received reports of an issue in which certain third-party applications may be unable to launch Microsoft Office apps or open Office documents after installing the Patch Tuesday. This affects both Windows 11 as well as Windows 10. The company says the problem impacts a subset of applications that rely on OLE (Object Linking and Embedding) automation to communicate with Microsoft Office programs. According to Microsoft, affected scenarios involve third-party software attempting to open Office applications or documents from within their own interface. In such cases, the Office program may fail to launch altogether, or the requested document may not open. Oddly there may not be any error message, which probably makes the issue difficult to diagnose. The bug affects several Office products, including Word, Excel, PowerPoint, Access, and other apps in the Microsoft Office suite when they are launched through the affected software. These include tax and accounting software such as CCH Engagement and Workpaper Manager, dental practice management solutions like Dentrix and Softdent, as well as the popular research and reference management tool Zotero. Microsoft adds that other applications using similar Office integration methods could also experience the same problematic behavior. To understand the issue it is important to look at OLE, the Microsoft technology involved. OLE allows different applications to work together and share data, while its Automation feature lets one program control another. Thus this enables third-party software to launch Microsoft Office apps, open documents, and perform tasks automatically without requiring users to switch between programs. Because many accounting, healthcare, research, and business applications rely on OLE automation to interact with Word, Excel, PowerPoint, and other Office apps, any disruption can break those workflows. As a result, affected software may be unable to open Office documents or launch Office applications even though the programs themselves continue to work normally. At the moment the company has not provided a permanent fix though it has confirmed that engineers are actively working on a resolution, which will be delivered through a future Windows update. As such additional details will be shared once more information becomes available. In the meantime, Microsoft recommends a simple workaround for affected users whic is to open the Office application or document directly rather than launching it through the third-party program. For enterprise customers and organizations managing larger deployments, Microsoft says an additional mitigation is available. Admins experiencing the problem on their managed devices are advised to contact Microsoft Support for business to obtain and apply the workaround.
    • It saddens me when cars are such dull colours now. Mine is bright metallic blue and I absolutely adore it for standing out in contrast to that depressing backdrop of traffic.
    • Sparkle 2.20.0 by Razvan Serea Sparkle is a free, open-source Windows optimization tool designed to make your PC faster, cleaner, and more private. With Sparkle, you can easily debloat Windows by removing unnecessary apps and services, disable Microsoft tracking to enhance privacy, and apply performance tweaks to boost speed. Its cleaner removes junk and temporary files, while every change is safe and fully reversible. Sparkle also features a modern, user-friendly interface with automatic updates, making system maintenance simple. Explore over 39 tweaks, from disabling telemetry and hibernation to optimizing network and game settings, all aimed at customizing and enhancing your Windows experience. Sparkle supports Windows 10 and 11. Sparkle 2.20.0 changelog: Debloat Tweak has animated border New homepage loading UI New Tweak Modal (Markdown Supported) Refactored GPU Detection Added Tests with vitest Added foobar2000 to apps Added Localsend to apps Updated Modal Styles Added styles for disabled inputs Added Animated Border to debloat-windows tweak Bumped dependencies Refactor System info logic for speed Tweak info modals now support Markdown Added Clear System info cache to settings Redesigned Home Page Loading UI Changed Some Icons around the app Download: Sparkle 2.20.0 | Portable | ~100.0 MB (Open Source) Links: Sparkle Website | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • lol it was a typo, fixed! haha imagine an actual 4TB Gen4 NVMe for $40 in 2026
  • Recent Achievements

    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      106
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!