Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 4

  • Download
  • Add to my manuals
  • Print
  • Page
    / 188
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 3
iv ServerIron ADX Firewall Load Balancing Guide
53-1002436-01
DRAFT: BROCADE CONFIDENTIAL
Chapter 2 Configuring Basic FWLB
In this chapter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Configuring basic Layer 3 FWLB. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Configuration guidelines. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Configuring basic Layer 3 FWLB . . . . . . . . . . . . . . . . . . . . . . . . .18
Configuration example for basic Layer 3 FWLB . . . . . . . . . . . . . . . .22
IPv4 example for basic Layer 3 FWLB . . . . . . . . . . . . . . . . . . . .22
IPv6 example for basic Layer 3 FWLB . . . . . . . . . . . . . . . . . . . . 24
Configuration examples with Layer 3 routing support . . . . . . . . . . .25
Basic FWLB with one sub-net and one virtual
routing interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
Basic FWLB with multiple sub-nets and multiple
virtual routing interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31
Chapter 3 Configuring HA FWLB
Understanding ServerIron FWLB . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
Layer 3 or Layer 4 sessions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 37
Session limits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .38
Session aging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .38
Configuring HA active-active FWLB . . . . . . . . . . . . . . . . . . . . . . . . . .39
Overview of active-active FWLB . . . . . . . . . . . . . . . . . . . . . . . . .39
HA FWLB configuration guidelines . . . . . . . . . . . . . . . . . . . . . . .40
Configuring the management IP address and
default gateway . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .42
Configuring the firewall port . . . . . . . . . . . . . . . . . . . . . . . . . . . .42
Configuring the partner port . . . . . . . . . . . . . . . . . . . . . . . . . . . .43
Configuring the additional data link (the always-active link) . .43
Configuring the router port . . . . . . . . . . . . . . . . . . . . . . . . . . . . .44
Configuring the firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .44
Adding the firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .44
Changing the maximum number of sessions . . . . . . . . . . . . . .46
Connection rate control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .46
Limiting the number of new connections for an application. . .46
Adding the firewalls to the firewall group . . . . . . . . . . . . . . . . . . 47
Changing the load balancing method. . . . . . . . . . . . . . . . . . . . . 47
Hashing load balance metric in FWLB . . . . . . . . . . . . . . . . . . . .48
Enabling the active-active mode. . . . . . . . . . . . . . . . . . . . . . . . .48
Configuring the paths and static MAC address entries. . . . . . .48
Dropping packets when a firewall reaches its limit . . . . . . . . . .50
Restricting TCP traffic to a firewall to established sessions . . .50
Complete CLI example. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51
Configuring active-active HA FWLB . . . . . . . . . . . . . . . . . . . . . . . . . .56
External ServerIron ADX standby A (Ext-SI-A) configuration . . . 57
External ServerIron ADX standby B (Ext-SI-B) configuration . . .58
Internal ServerIron ADX C (Int-SI-C) Configuration. . . . . . . . . . .60
Internal ServerIron ADX D (Int-SI-D) configuration. . . . . . . . . . . 61
Configuring active-active HA FWLB with VRRP . . . . . . . . . . . . . . . . .62
Overview of active-active FWLB with VRRP . . . . . . . . . . . . . . . .62
Page view 3
1 2 3 4 5 6 7 8 9 ... 187 188

Comments to this Manuals

No comments