ServerIron ADX Firewall Load Balancing Guide 21
53-1002436-01
Configuration guidelines
2
DRAFT: BROCADE CONFIDENTIAL
For many configurations, static MAC entries are required. Where required, you must add a static
MAC entry for each firewall interface with the ServerIron ADX. The FWLB configuration examples in
this guide indicate whether static MAC entries are required.
To configure the paths and static MAC entries for the configuration shown in Figure 2 on page 11,
enter the following commands. Note that the following example uses the IPv4 address format and
firewall group 2. Enter the first group of commands on ServerIron ADX A. Enter the second group of
commands on ServerIron ADX B.
Commands for ServerIron ADX A (external)
ServerIron ADX(config)# server fw-group 2
ServerIron ADX(config-fw-2)# fwall-info 1 3 209.157.23.3 209.157.22.3
ServerIron ADX(config-fw-2)# fwall-info 2 5 209.157.23.3 209.157.22.4
ServerIron ADX(config-fw-2)# exit
ServerIronADX(config)# vlan 1
ServerIron ADX(config-vlan-1)# static-mac-address abcd.4321.34e0 ethernet 3
priority 1 router-type
ServerIron ADX(config-vlan-1)# static-mac-address abcd.4321.34e1 ethernet 5
priority 1 router-type
ServerIron ADX(config)# write mem
Commands for ServerIron ADX B (internal)
ServerIron ADX(config)# server fw-group 2
ServerIron ADX(config-fw-2)# fwall-info 1 1 209.157.22.2 209.157.23.1
ServerIron ADX(config-fw-2)# fwall-info 2 2 209.157.22.2 209.157.23.2
ServerIron ADX(config-fw-2)# exit
ServerIronADX(config)# vlan 1
ServerIron ADX(config-vlan-1)# static-mac-address abcd.4321.34e2 ethernet 1
priority 1 router-type
ServerIron ADX(config-vlan-1)# static-mac-address abcd.4321.34e3 ethernet 2
priority 1 router-type
ServerIron ADX(config)# write mem
Syntax: (IPv4) server fw-group 2
Syntax: (IPv4) [no] fwall-info <path-num> <portnum> <other-ip> <next-hop-ip>
Syntax: (IPv6) server fw-group 4 ipv6
Syntax: (IPv6) [no] fwall-info <path-num> <portnum> <other-ipv6> <next-hop-ipv6>
The other ServerIron ADX’s IP address and next-hop IP address parameters must be both IPv4
addresses or both IPv6 addresses. IPv4 and IPv6 addresses cannot be mixed.
You must use IPv4 addresses for IPv4 firewalls and IPv6 addresses for IPv6 firewalls. If the same
firewall supports both IPv4 and IPv6, you must configure them separately under group 2 (IPv4) and
group 4 (IPv6).
The <path-num> parameter specifies the path. The sequence of path IDs must be contiguous from
start to finish.
The <portnum> parameter specifies the port that connects the ServerIron ADX to the firewall. If the
port number is dynamic, use port number 65535.
Comments to this Manuals