A WAN port can connect a private network to Alibaba Cloud. This topic describes how to configure a WAN port for a Smart Access Gateway (SAG) device in the SAG console.
Features of a WAN port
- SNAT
After you enable SNAT, private source IP addresses are converted into public IP addresses that can access the Internet. By default, SNAT is disabled.
In inline mode, you must enable SNAT for an SAG device to connect on-premises networks to the Internet. In one-arm mode, we recommend that you disable SNAT.
- FAQ about custom DNS servers
By default, the WAN port directly accesses Alibaba Cloud DNS servers. You can specify a custom DNS server for the WAN port.
- Bandwidth throttling
You can set bandwidth throttling for the WAN port. You can use quality of service (QoS) policies and bandwidth throttling to improve bandwidth utilization.
- High-availability connections over WAN ports
You can configure multiple WAN ports for an SAG device. The WAN ports can be used to establish high-availability connections, balance loads, and improve the network availability.
- By default, port 5 of an SAG-1000 device serves as a WAN port. You can also specify other ports as WAN ports.
- The number of WAN ports supported by an SAG-100WM device is based on the device type. Type 2 devices support multiple WAN ports. Type 1 devices support only one WAN port. The exterior of Type 1 and Type 2 devices is different.
You can specify the priority, ISP, and weight properties to manage priorities of WAN ports. The priorities of the properties in descending order: priority>ISP>weight.
Manage properties Description Scenarios Priority If you have configured multiple WAN ports for an SAG device, you can set a priority for each WAN port. The port that has the highest priority is used as the active port. Ports that have lower priorities are used as standby ports. An SAG device preferentially uses the active port to forward traffic. If the active port is not working as expected, standby ports automatically take over.
- If the WAN ports are assigned different priorities, the SAG device can establish high-availability connections by using the active port and standby ports.
- If the WAN ports are assigned the same priority, the SAG device can implement load balancing for the WAN ports based on the ISP and weight properties.
ISP If the WAN ports are assigned the same priority, the SAG device matches data packets with Internet service provider (ISP) connections based on the destination IP addresses specified in the data packets. This implements load balancing. Weight If the ISP configurations of the WAN ports are the same or the SAG device cannot find ISPs that match the data packets, the SAG device implements load balancing based on the weights of the WAN ports. Note- You can specify an ISP for each WAN port only if the SAG instance is deployed in the mainland China area.
- The WAN ports can be used to balance only the load of network traffic transmitted over public networks.
Configure a WAN port
References
- What is a QoS policy?
- Deployment modes
- Descriptions of SAG-100WM
- ModifySagWan: modifies configurations for WAN ports of SAG devices.
- ModifySagWanSnat: modifies SNAT configurations for WAN ports of SAG devices.
- ModifySagUserDns: modifies DNS configurations for WAN ports of SAG devices.