Brocade Communications Systems ServerIron ADX 12.4.00 Service Manual Page 63

  • Download
  • Add to my manuals
  • Print
  • Page
    / 188
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 62
52 ServerIron ADX Firewall Load Balancing Guide
53-1002436-01
Configuring HA active-active FWLB
3
DRAFT: BROCADE CONFIDENTIAL
The following commands configure the firewalls and add them to the firewall group. Because an
application port is configured on each firewall, the ServerIron ADX will use Layer 4 sessions to load
balance the firewall traffic for that application. The ServerIron ADX will use Layer 3 sessions to load
balance traffic for other applications.
SI-Ext-A(config)# server fw-name FW1 10.10.1.1
SI-Ext-A(config-rs-FW1)# port http
SI-Ext-A(config-rs-FW1)# exit
SI-Ext-A(config)# server fw-name FW2 10.10.1.2
SI-Ext-A(config-rs-FW2)# port http
SI-Ext-A(config-rs-FW2)# server fw-group 2
SI-Ext-A(config-fw-2)# fw-name FW1
SI-Ext-A(config-fw-2)# fw-name FW2
The following command enables the active-active mode. The CLI requires a number from 1 through
255. See
“Enabling the active-active mode” on page 48 for more details.
SI-Ext-A(config-fw-2)# sym-priority 1
The following commands configure the data paths through the firewalls and to the default gateway
router. The l2-fwall command is part of the always-active feature and is required if you use the
always-active command.
SI-Ext-A(config-fw-2)# fwall-info 1 4/1 10.10.2.222 10.10.1.1
SI-Ext-A(config-fw-2)# fwall-info 2 4/5 10.10.2.222 10.10.1.2
SI-Ext-A(config-fw-2)# fwall-info 3 4/1 10.10.2.223 10.10.1.1
SI-Ext-A(config-fw-2)# fwall-info 4 4/5 10.10.2.223 10.10.1.2
SI-Ext-A(config-fw-2)# fwall-info 5 4/12 10.10.1.101 10.10.1.101
SI-Ext-A(config-fw-2)# l2-fwall
SI-Ext-A(config-fw-2)# exit
The following commands add static entries to the ServerIron ADX’s MAC table for the firewall
interfaces. Specify a priority higher than 0. You can specify a priority up to 7. The router-type
parameter is required for FWLB.
The following commands also enable FWLB and save the configuration changes to the
startup-config file.
SI-Ext-A(config)# vlan 1
SI-Ext-A(config-vlan-1)# static-mac-address 0050.da8d.5218 ethernet 4/1 priority
1
router-type
SI-Ext-A(config-vlan-1)# static-mac-address 0050.da92.08fc ethernet 4/5 priority
1
router-type
SI-Ext-A(config-vlan-1)# exit
SI-Ext-A(config)# write memory
Page view 62
1 2 ... 58 59 60 61 62 63 64 65 66 67 68 ... 187 188

Comments to this Manuals

No comments