GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from

Home » GFI User Forums » Kerio Control » Restricting a group from an interface (Trying to restrict fallback to a particular interface)
Restricting a group from an interface [message #146027] Fri, 21 June 2019 16:18
monopoly is currently offline  monopoly
Messages: 1
Registered: June 2019

Kerio Control Box NG500 Series (9.3.0 build 3273)

I have a relatively straightforward situation (I think), but it's not working out for me:

I have 3 Internet Group interfaces (Interface-1, Interface-2, Interface-3), and 3 groups (Group-1, Group-2, Group-3)

(1) G-1 should always use I-1. If and only if I-1 is down, they can fallback to I-2. They should not fallback to I-3.
(2) G-2 should always use I-2. If and only if I-2 is down, they can fallback to I-1. They should not fallback to I-3.
(3) G-3 should always use I-3. No fallback is needed.

Internet interfaces are set for load balancing (although in reality there is no LB happening, as each group is directed to a specific interface). I-3 is not set to load balance

I have everything set up and working OK. To enable (1) and (2) I have clicked "Use other interfaces when this interface is unavailable" on the traffic rules )NAT Translation) for Group-1 and Group-2.

The problem is that when Interface-2 goes down, traffic for Group-2 gets redirected to both Interface-1 and Interface-3. How can I forbid fallback to Interface-3?

I've read multiple articles here about load-balancing and fallback, and none seem to cover this case.

Thanks in advance for any advice.


[Updated on: Fri, 21 June 2019 17:23]

Report message to a moderator

Previous Topic: License quota exhausts soon alerts
Next Topic: HA by LAN interfaces
Goto Forum:

Current Time: Tue Sep 26 17:27:01 CEST 2023

Total time taken to generate the page: 0.08637 seconds