86 ServerIron ADX Firewall Load Balancing Guide
53-1002436-01
Configuration example for a high-availability multizone FWLB
4
DRAFT: BROCADE CONFIDENTIAL
Commands on Zone1-SI-S in zone 1
The following commands configure ServerIron ADX “Zone1-SI-S” on the right side of zone 1 in
Figure 14 on page 79. The configuration is similar to the one for Zone1-SI-A, with the following
exceptions:
• The management IP address is different.
• The default gateway goes to firewall FW2’s interface with the ServerIron ADX. (The default
gateway for Zone1-SI-A goes to FW1’s interface with that ServerIron ADX.)
• The priority is set to 1 instead of 255. The lower priority makes this ServerIron ADX the standby
ServerIron ADX by default.
• The paths are different due to the ServerIron ADX’s placement in the network. (However, like
Zone1-SI-A, ServerIron ADX Zone1-SI-S has a path through each firewall to each of the
ServerIron ADXs in the other zones, and has a path to its directly attached router.)
ServerIronADX(config)# hostname Zone1-SI-S
Zone1-SI-S(config)# ip address 209.157.24.14 255.255.255.0
Zone1-SI-S(config)# ip default-gateway 209.157.24.254
Zone1-SI-S(config)# no span
Zone1-SI-S(config)# server router-ports 5
Zone1-SI-S(config)# server fw-port 9
Zone1-SI-S(config)# trunk switch ethernet 9 to 10
Zone1-SI-S(config)# trunk deploy
Zone1-SI-S(config)# vlan 10 by port
Zone1-SI-S(config-vlan-10)# untagged 9 to 10
Zone1-SI-S(config-vlan-10)# exit
Zone1-SI-S(config)# vlan 1
Zone1-SI-S(config-vlan-1)# always-active
Zone1-SI-S(config-vlan-1)# exit
Zone1-SI-S(config)# server fw-name FW1 209.157.24.1
Zone1-SI-S(config-rs-FW1)# exit
Zone1-SI-S(config)# server fw-name FW2 209.157.24.254
Zone1-SI-S(config-rs-FW2)# exit
Zone1-SI-S(config)# access-list 2 permit 209.157.25.0 0.0.0.255
Zone1-SI-S(config)# server fw-group 2
Zone1-SI-S(config-fw-2)# fwall-zone Zone2 2 2
Zone1-SI-S(config-fw-2)# fw-name FW1
Zone1-SI-S(config-fw-2)# fw-name FW2
Zone1-SI-S(config-fw-2)# l2-fwall
Zone1-SI-S(config-fw-2)# sym-priority 1
Zone1-SI-S(config-fw-2)# fwall-info 1 16 209.157.23.11 209.157.24.1
Zone1-SI-S(config-fw-2)# fwall-info 2 16 209.157.23.12 209.157.24.1
Zone1-SI-S(config-fw-2)# fwall-info 3 1 209.157.23.11 209.157.24.254
Zone1-SI-S(config-fw-2)# fwall-info 4 1 209.157.23.12 209.157.24.254
Zone1-SI-S(config-fw-2)# fwall-info 5 16 209.157.25.15 209.157.24.1
Zone1-SI-S(config-fw-2)# fwall-info 6 16 209.157.25.16 209.157.24.1
Zone1-SI-S(config-fw-2)# fwall-info 7 1 209.157.25.15 209.157.24.254
Zone1-SI-S(config-fw-2)# fwall-info 8 1 209.157.25.16 209.157.24.254
Zone1-SI-S(config-fw-2)# fwall-info 9 5 209.157.24.251 209.157.24.251
Zone1-SI-S(config-fw-2)# exit
Zone1-SI-S(config)# vlan 1
Zone1-SI-S(config-vlan-1)# static-mac-address abcd.5200.348d ethernet 1 priority
1 router-type
Zone1-SI-S(config-vlan-1)# static-mac-address abcd.5200.0b50 ethernet 16 priority
1 router-type
Comments to this Manuals