Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 115

  • Download
  • Add to my manuals
  • Print
  • Page
    / 188
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 114
104 ServerIron ADX Firewall Load Balancing Guide
53-1002436-01
Configuration examples with Layer 3 routing
4
DRAFT: BROCADE CONFIDENTIAL
Zone1-SI-A(config-ve-2)# ip address 10.10.7.101 255.255.255.0
Zone1-SI-A(config-ve-2)# exit
The following command configures an IP default route. The next hop for this route is the ServerIron
ADX’s interface with firewall FW1.
Zone1-SI-A(config)# ip route 0.0.0.0 0.0.0.0 10.10.1.1
The following command configures a static route to the sub-net that contains the external host.
Zone1-SI-A(config)# ip route 20.20.0.0 255.255.0.0 10.10.7.100
The following commands configure the synchronization link between this ServerIron ADX and
ServerIron ADX Zone1-SI-B. For redundancy, the link is configured on a trunk group.
Zone1-SI-A(config)# vlan 10
Zone1-SI-A(config-vlan-10)# untagged ethernet 4/9 to 4/10
Zone1-SI-A(config-vlan-10)# exit
Zone1-SI-A(config)# trunk switch ethernet 4/9 to 4/10
Zone1-SI-A(config)# trunk deploy
Zone1-SI-A(config)# server fw-port 4/9
The following commands configure the data link connecting this ServerIron ADX to its partner,
Zone1-SI-B. For redundancy, the link is configured as a two-port trunk group.
Zone1-SI-A(config)# trunk switch ethernet 4/11 to 4/12
Zone1-SI-A(config)# trunk deploy
Zone1-SI-A(config)# server partner-ports ethernet 4/11
Zone1-SI-A(config)# server partner-ports ethernet 4/12
Zone1-SI-A(config)# server fw-group 2
Zone1-SI-A(config-fw-2)# l2-fwall
Zone1-SI-A(config-fw-2)# exit
The following commands add the firewalls. Three application ports (HTTP, FTP, and SNMP) are
configured on each of the firewalls. The no-health-check parameter disables the Layer 4 health
check for the specified application.
Zone1-SI-A(config)# server fw-name fw1 10.10.1.1
Zone1-SI-A(config-rs-fw1)# port http
Zone1-SI-A(config-rs-fw1)# port http no-health-check
Zone1-SI-A(config-rs-fw1)# port snmp
Zone1-SI-A(config-rs-fw1)# port snmp no-health-check
Zone1-SI-A(config-rs-fw1)# exit
Zone1-SI-A(config)# server fw-name fw2 10.10.1.2
Zone1-SI-A(config-rs-fw2)# port http
Zone1-SI-A(config-rs-fw2)# port http no-health-check
Zone1-SI-A(config-rs-fw2)# port snmp
Zone1-SI-A(config-rs-fw2)# port snmp no-health-check
Zone1-SI-A(config-rs-fw2)# exit
The following commands add the firewall definitions to the firewall port group (always group 2).
Zone1-SI-A(config)# server fw-group 2
Zone1-SI-A(config-fw-2)# fw-name fw1
Zone1-SI-A(config-fw-2)# fw-name fw2
The following command enables the active-active mode. For details about configuring this
command, refer to
“Enabling the active-active mode” on page 48.
Zone1-SI-A(config-fw-2)# sym-priority 255
Page view 114
1 2 ... 110 111 112 113 114 115 116 117 118 119 120 ... 187 188

Comments to this Manuals

No comments