Hi @Steve,
sure, I have a few scenarios in mind. Let me anwser your question and share two examples.
If ping to the target host fails and the corresponding OBP rule is disabled, should traffic matching that rule use some alternative path, or should it simply be blocked?
OBP settings already allow us to choose what happens when “No Connections are Available”. We can either choose “Drop the traffic” or “Fall-through to the Next Rule”.
I imagine that if the ping failed, it would trigger the OBP rule to use another interface from the priority list. If all interfaces fail, the OBP would follow the previously set rule: either “drop the traffic” or “fall-through”.
Example 1
I use OBP to send all traffic (including IC2) to an L3SF VPN profile. In case of network issues behind a VPN Hub, the traffic from the remote site is still routed to L3SF, but can’t pass through devices up the route and can’t reach the Internet.
The VPN tunnel is still on, thus the OBP rule is active, but the remote site can’t reach the Internet.
This is a real-life scenario, where hundreds our Customer’s routers went offline in InControl2, because one of the network elements behind VPN hub couldn’t route traffic to IC2.
If the OBP rule on remote CPE could ping IC2 to verify the health of the interface it currently uses it would know when to switch from Interface with Priority 1 to Priority 2 (cellular).
Example 2
Our Customers use L3SF to distribute traffic from remote sites to one of a few VPN Hubs with different priorities. Like in example 1, sometimes a VPN profile is on even if other elements behind the VPN hub fail and can’t carry the traffic further. In that case, we need the remote CPEs to re-route all traffic from the primary L3SF to the secondary profile.
This issue mostly occurs when the remote traffic is routed by VPN hub from L3SF to its LAN interface (a common case in telco deployments). WAN healthcheck allows us to monitor network issues, but LAN does not.
In some cases, we can bypass those issues with BGP, but it is not always possible.
I hope what I described makes sense. I can share more details if needed 