Policy-Based Routing and WAN Failover Configuration on Edge Servers
Learn how to design resilient corporate networks by combining multiple internet links with intelligent routing and automatic failover using Linux edge servers.
Summary
- Using multiple internet links simultaneously eliminates single points of failure and distributes corporate traffic efficiently.
- Policy-based routing allows directing specific packets based on source, destination, or logical port parameters.
- Continuous health check mechanisms detect link drops before users even notice service interruptions.
- The default routing table is no longer sufficient when dynamic balancing and state retention are required.
- Configuring packet marking with iptables simplifies the Linux kernel's job when handling additional routing tables.
Edge Architecture with Multiple Internet Links
In modern corporate environments, relying on a single internet connection is an unacceptable operational risk. When the primary provider goes down, the entire operation halts, causing financial loss and user frustration. The solution lies in deploying edge servers, which act as intelligent gatekeepers for the network, managing data ingress and egress between the company and the outside world.
In practice, this means connecting two or more internet links—perhaps a dedicated fiber optic line and a backup coaxial cable or radio link—into a single computer equipped with the Linux operating system. This server takes on the responsibility of deciding which path each data packet should take to reach its destination with maximum efficiency and the lowest possible delay.
The Role of Policy-Based Routing
Traditional routing, which comes configured by default on most home routers, looks only at the destination IP address to decide where to send a packet. However, in a scenario with multiple WAN links, which are long-distance connections with the internet service provider, this simple logic fails because return traffic can get lost if the chosen path does not match the original source.
Policy-based routing, known technically as PBR, breaks this rigid rule by allowing the administrator to create rules based on additional criteria, such as the sender's IP address or the service port used. In practice, you can determine that all traffic from the finance department must leave through the faster fiber optic connection, while regular web browsing traffic uses the cheaper backup link.
Configuring Additional Routing Tables in Linux
To put this architecture into practice using the Linux kernel, we need to go beyond the default routing table and create customized tables for each provider. Each additional route table works as an isolated traffic map, telling the packets exactly which gateway, the IP address of the provider's router, they should be delivered to.
The ip route command allows usidity us to define these tables and associate specific rules with them. The following list demonstrates the basic commands executed in the server terminal to structure this multi-path routing securely:
- Open the system routing tables configuration file to register the numerical and textual identifiers for the new carrier routes.
echo '200 wan1' >> /etc/iproute2/rt_tables echo '300 wan2' >> /etc/iproute2/rt_tables - Add default routes for each table, pointing to the respective internet provider gateways.
ip route add default via 192.168.1.1 dev eth1 table wan1 ip route add default via 10.0.0.1 dev eth2 table wan2 - Create policy rules to direct traffic originating from specific subnets to their corresponding tables.
ip rule add from 192.168.100.0/24 table wan1 ip rule add from 192.168.200.0/24 table wan2
Implementing Automatic Failover with Health Monitoring
Having multiple links connected solves nothing if the server keeps sending data to a provider that is physically disconnected or experiencing severe instability. Automatic failover is the system's ability to detect this failure and redirect all remaining traffic to the secondary link in fractions of a second, without human intervention.
To achieve this behavior, we use monitoring scripts known as ping checkers or dedicated tools, such as Netdata or bash scripts that periodically test connectivity with reliable external addresses, like public DNS servers. When the server detects consecutive failures on a link, it automatically removes the associated routing rule, forcing the system to use the surviving route.
Final Thoughts on Edge Resilience
Building a resilient network edge with multiple links and intelligent routing requires rigorous planning, stress testing, and continuous monitoring. Although the initial investment of time in configuring tables and policies in Linux may seem complex, the return in terms of operational stability amply compensates for the technical effort applied.
Keeping packet marking rules simple and ensuring that failover scripts are fast and reliable will prevent future headaches. With a well-designed infrastructure, your company gains the necessary autonomy to navigate smoothly, knowing that connection drops no longer mean business interruptions.