Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 156

  • Download
  • Add to my manuals
  • Print
  • Page
    / 188
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 155
ServerIron ADX Firewall Load Balancing Guide 145
53-1002436-01
Configuration example for FWLB-to-SLB
6
DRAFT: BROCADE CONFIDENTIAL
ServerIronADXB(config)# server virtual www.brocade.com
ServerIronADXB(config-vs-www.brocade.com)# bind http RS1 http
ServerIronADXB(config-vs-www.brocade.com)# bind http RS2 http
Enter the following command to enable FWLB-to-SLB.
NOTE
This command applies only to the ServerIron ADX that contains the SLB configuration. Do not enter
this command on the Internet ServerIron ADX (ServerIron ADXA).
ServerIronADXB(config)# server fw-slb
Enter the following commands to complete the FWLB configuration on this ServerIron ADX. Notice
that the fwall-info commands configure paths that are reciprocal to the paths configured on
ServerIron ADX A. Path 1 on each ServerIron ADX goes through one of the firewalls while path 2
goes through the other firewall.
ServerIronADXB(config)# server fw-name FW1-IPout 192.168.2.30
ServerIronADXB(config-rs-FW1-IPout)# exit
ServerIronADXB(config)# server fw-name FW2-IPout 192.168.2.40
ServerIronADXB(config-rs-FW2-IPout)# exit
ServerIronADXB(config)# server fw-group 2
ServerIronADXB(config-fw-2)# fw-name FW1-IPout
ServerIronADXB(config-fw-2)# fw-name FW2-IPout
ServerIronADXB(config-fw-2)# fwall-info 1 1 192.168.1.100 192.168.2.30
ServerIronADXB(config-fw-2)# fwall-info 2 2 192.168.1.100 192.168.2.40
ServerIronADXB(config-fw-2)# exit
ServerIronADXB(config)# static-mac-address abcd.4321.34e2 ethernet 1 priority 1
router-type
ServerIronADXB(config)# static-mac-address abcd.4321.34e3 ethernet 2 priority 1
router-type
ServerIronADXB(config)# write memory
Active-active FWLB – with external SLB (FWLB-to-SLB)
The software supports two types of FWLB with SLB configurations. Your choice of implementation
depends on which pair of ServerIron ADXs you want to use for the SLB configuration. Use
SLB-to-FWLB is you want to place the SLB configuration on the external ServerIron ADXs. Use
FWLB-to-SLB if you want to place the SLB configuration on the internal ServerIron ADXs.
The software supports the following configurations:
FWLB-to-SLB – The internal ServerIron ADX (the one on the server side or private side of the
firewalls) contains all the SLB configuration information. In this configuration, the
FWLB-to-SLB feature is enabled on the internal ServerIron ADX rather than the external
ServerIron ADX. This configuration enables the internal ServerIron ADX to learn the firewall
from which a client request is received and send the server reply back through the same
firewall.
SLB-to-FWLB – The external ServerIron ADX, on the client or external side of the firewalls,
performs FWLB for traffic directed toward real servers connected to the ServerIron ADX on the
private side of the firewalls. In this configuration, all the SLB configuration (virtual IP address,
real server, and port bindings) resides on the external ServerIron ADX. The real servers are
configured as remote servers. In addition, the SLB-to-FWLB feature is enabled on the external
ServerIron ADX. The internal ServerIron is configured for FWLB but requires no additional
configuration.
Page view 155
1 2 ... 151 152 153 154 155 156 157 158 159 160 161 ... 187 188

Comments to this Manuals

No comments