Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 62

  • Download
  • Add to my manuals
  • Print
  • Page
    / 188
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 61
ServerIron ADX Firewall Load Balancing Guide 51
53-1002436-01
Configuring HA active-active FWLB
3
DRAFT: BROCADE CONFIDENTIAL
Syntax: [no] server fw-strict-sec
The feature applies globally to all TCP traffic received for FWLB.
Complete CLI example
The following sections show the CLI commands for configuring the ServerIron ADXs in Figure 10.
Commands on ServerIron ADX SI-Ext-A
The following commands add a management IP address and default gateway address to the
ServerIron ADX. The IP address must be in the same sub-net as the ServerIron ADX’s interfaces
with the Layer 3 firewalls.
ServerIronADX> enable
ServerIronADX# configure terminal
ServerIronADX(config)# hostname SI-Ext-A
SI-Ext-A(config)# ip address 10.10.1.111 255.255.255.0
SI-Ext-A(config)# ip default-gateway 10.10.1.101
The following commands configure trunk groups for the synchronization link and the additional
data link between this ServerIron ADX and its high-availability partner.
SI-Ext-A(config)# trunk switch ethernet 4/5 to 4/6
SI-Ext-A(config)# trunk deploy
SI-Ext-A(config)# trunk switch ethernet 4/13 to 4/14
SI-Ext-A(config)# trunk deploy
The following commands enable the always-active feature and disable the Spanning Tree Protocol
(STP) in VLAN 1, which contains the ports that will carry the FWLB traffic.
SI-Ext-A(config)# vlan 1
SI-Ext-A(config-vlan-1)# always-active
SI-Ext-A(config-vlan-1)# no spanning-tree
SI-Ext-A(config-vlan-1)# exit
The following commands configure the ports for the synchronization link to the other ServerIron
ADX in a separate port-based VLAN. The separate VLAN is required. Add the ports as untagged
ports.
SI-Ext-A(config)# vlan 2 name sync_link by port
SI-Ext-A(config-vlan-2)# untagged ethernet 4/13 to 4/14
SI-Ext-A(config-vlan-2)# no spanning-tree
SI-Ext-A(config-vlan-2)# exit
The server fw-port command identifies the port that connects this ServerIron ADX to its
high-availability partner. The server partner-ports command identifies the data link that connects
this ServerIron ADX to its high-availability partner to reach the firewalls. If you use a trunk group,
specify the first port in the group (the group’s primary port).
SI-Ext-A(config)# server fw-port 4/13
SI-Ext-A(config)# server partner-ports ethernet 4/5
The server router-port command identifies the port that connects this ServerIron ADX to its default
gateway router.
SI-Ext-A(config)# server router-port 4/12
Page view 61
1 2 ... 57 58 59 60 61 62 63 64 65 66 67 ... 187 188

Comments to this Manuals

No comments