EasyManua.ls Logo

Enterasys Matrix DFE-Gold Series

Enterasys Matrix DFE-Gold Series
944 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring Load Sharing Network Address Translation (LSNAT)
Enterasys Matrix DFE-Gold Series Configuration Guide 19-3
wouldonlyrequiretheuseofonebindinghardwareresource(insteadofoneperserviceper
client).
Inordertousestickypersistence,thefollowingconfigurationcriteriaarerequired:
•Stickypersistencemustbeconfiguredfortheserverfarmgroup(withthestickycommand)as
wellasforthevirtualserver(withthe
persistencelevelcommand).
•Therealserversinthisserverfarmaretobeusedforallservices.Theserversarenotallowed
tobeusedwithotherserverfarmstosupportothervirtualserverservices.Thereisone
exceptiontothisrule,describedinthenextbulletitem.
•Stickymeansall
TCPportsorallUDPportsonthevirtualserveraresupported,butnotboth.
YoucancreatetwovirtualserverswithdifferentIPaddresses(oneforTCPprotocolsandone
forUDPprotocols/ports)andusethesamerealservers(withdifferentserverfarmnames).
ThatwayallTCPandUDPports
aresupportedbythesamesetofrealservers.
•Port0inthevirtualserverhastobeusedtosupportthisserviceandisreservedforthis
purpose.
•TheserviceFTPconfigurationisnotneededforthistypeofpersistence.(Seethevirtual
command,virtualonpage 1922.)
Configuring Direct Access to Real Servers
WhentheLSNATrouterhasbeenconfiguredwithloadbalancingserverfarmgroups,withreal
serversandvirtualserversconfiguredand“inservice,”therealserversareprotectedfromdirect
clientaccessforallservices.Loadsharingclientscanonlyaccessspecificservicesonthereal
serversbymeansofthe
virtualserversconfiguredtoprovidethoseservices.
Ifyoualsowanttoprovidedirectclientaccesstorealserversconfiguredaspartofaserverfarm
group,therearetwomechanismsthatcanprovidedirectclientaccess.
Thefirstmechanism,configuredwithinvirtualserverconfigurationmodewiththeallow
accessserverscommand,
allowsyoutoidentifyspecificclientswhocansetupconnections
directlytoarealserversIPaddress,aswellascontinuetousethevirtualserverIPaddress.
Thesecondmechanism,configuredinGlobalconfigurationmodewiththeipslballowaccess_all
command,allowsallclientstodirectlyaccessallservices
providedbyrealservers,exceptforthose
servicesconfiguredtobeaccessedbymeansofaconfiguredvirtualserver.Therealserversarestill
protectedfromdirectclientaccessforconfiguredservicesonly.Forexample,usingthis
mechanism,ifyouconfiguredaloadbalancingservergroupcontaining“realserver1”and
“realserver2”
toprovideHTTPservicethroughvirtualserver“vserverhttp,”clientscanonly
accesstheHTTPserviceonthoserealserversbymeansofthe“vserverhttp”virtualserver.
However,clientscandirectlyaccess“realserver1”and“realserver2”foranyservicesotherthan
HTTP.
Ifyoucombinethetwomechanisms,thatis,configure
ipslballowaccess_allattheGlobal
configurationmodeandalsoconfigureallowaccessserverswithinavirtualserversconfiguration
mode,theclientsidentifiedwiththeallowaccessserverscommandwillhavedirectaccesstothe
realserversforallservices(includingthoseprovidedbyavirtualserver)andbeblockedfrom
using
thevirtualserver.Soforexample,an“allowed”clientcanaccess“realserver1”and
“realserver2”directlyforallservices,includingHTTP,butcannotaccessthoseserversforHTTP
bymeansofthe“vserverhttp”virtualserver.
Service Verification
UPDportserviceverificationcanbeenabledononeormoreloadbalancingservers.Thefirmware
accomplishesthisbysendingaUDPpacketwith“\r\n”(CarriageReturn/LineFeed)asdatato

Table of Contents

Related product manuals