Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 68

  • Download
  • Add to my manuals
  • Print
  • Page
    / 188
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 67
ServerIron ADX Firewall Load Balancing Guide 57
53-1002436-01
Configuring active-active HA FWLB
3
DRAFT: BROCADE CONFIDENTIAL
In the topology presented in this section, IP addresses of firewalls are different on each
ServerIron ADX. Use the other-ip command under the firewall configuration level to identify the
partner ServerIron ADX’s firewall address.
Syntax: [no] other-ip <ip-addr> | <ipv6-addr>
NOTE
IPv4 and IPv6 address formats cannot be mixed. Addresses must be entered in the same
format.
This topology assumes that OSPF is running on firewalls, external routers, and internal routers.
These devices exchange OSPF messages (multicast packets) among them. When a ServerIron
ADX is in state 3, it will block multicast packets. In the attached topology, if Ext-SI-B is in state
3, it will block the OSPF multicast packets sent by the firewalls and Ext-Router-2 to prevent
Ext-Router-2 and the firewalls from learning OSPF routes through each other. Ext-Router-2
learns the OSPF routes of internal networks through Ext-Router-1. All the external traffic will be
going to Ext-SI-A.
If the design requires ServerIron ADX (in state 3) not to block multicast packets, the server
fw-allow-multicast command must be configured on the ServerIron ADXs. When the command
is configured, the external routers can learn the OSPF routes from the firewalls and traffic can
go to both ServerIron ADXs.
Note that the following example uses the IPv4 address format and firewall group 2.
External ServerIron ADX standby A (Ext-SI-A) configuration
SI-StandbyA(config)# trunk switch ethernet 2/7 to 2/8
SI-StandbyA(config)# server fw-port 2/7
SI-StandbyA(config)# server partner-ports ethernet 4/5
SI-StandbyA(config)# server router-ports ethernet 2/1
SI-StandbyA(config)# server fw-name fw1 20.20.1.1
SI-StandbyA(config-rs-FW1)# other-ip 20.20.8.1
SI-StandbyA(config-rs-FW1)# port http
SI-StandbyA(config-rs-FW1)# port http no-health-check
SI-StandbyA(config-rs-FW1)# port http url "HEAD /"
SI-StandbyA(config-rs-FW1)# exit
SI-StandbyA(config)# server fw-name fw2 20.20.1.2
SI-StandbyA(config-rs-FW2)# other-ip 20.20.8.2
SI-StandbyA(config-rs-FW2)# port http
SI-StandbyA(config-rs-FW2)# port http no-health-check
SI-StandbyA(config-rs-FW2)# port http url "HEAD /"
SI-StandbyA(config-rs-FW2)# exit
SI-StandbyA(config)# server fw-name fw3 20.20.1.3
SI-StandbyA(config-rs-FW3)# other-ip 20.20.8.3
SI-StandbyA(config-rs-FW3)# port http
SI-StandbyA(config-rs-FW3)# port http no-health-check
SI-StandbyA(config-rs-FW3)# port http url "HEAD /"
SI-StandbyA(config-rs-FW3)# exit
SI-StandbyA(config)# server fw-name fw4 20.20.1.4
SI-StandbyA(config-rs-FW4)# other-ip 20.20.8.4
SI-StandbyA(config-rs-FW4)# port http
SI-StandbyA(config-rs-FW4)# port http no-health-check
SI-StandbyA(config-rs-FW4)# port http url "HEAD /"
Page view 67
1 2 ... 63 64 65 66 67 68 69 70 71 72 73 ... 187 188

Comments to this Manuals

No comments