EasyManua.ls Logo

Enterasys Matrix DFE-Gold Series

Enterasys Matrix DFE-Gold Series
944 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring Load Sharing Network Address Translation (LSNAT)
19-4 LSNAT Configuration
theUDPport.IftheserverrespondswithanICMP“PortUnreachable”message,itisconcluded
thattheportisnotactiveandtheserverisreportedas“DOWN”.Otherwise,iftheservereither
getsdatabackfromtherequesttotheserverordoesnotgetanyresponseatall,
itisassumedthat
theportisactiveandtheserverisreportedas“UP”.Thelackofaresponsecouldalsobethe
resultoftheserveritselfnotbeingavailableandcouldproduceanerroneousindicationofthe
serverbeing“UP”.ToavoidthiswhenrequestinganAPP
UDPonaUDPport,anICMPpingis
issuedfirsttoinsurethattheserverisavailablebeforesubmittingtheAPPUDPrequest.This
preventsasituationwheretheUDPportwillnotreturna“PortUnreachable”becauseofthe
serveritselfbeingdown,resultinginLSNATrespondingwitha
falseindicationthattheUDPport
is“UP”.
Application Content Verification (ACV)
ApplicationContentVerification(ACV)canbeenabledonaporttoverifythecontentofan
applicationononeormoreloadbalancingservers.ACVisamethodofensuringthatdatacoming
fromyourserversremainsintactanddoesnotchangewithoutyourknowledge.ACVcan
simultaneouslyprotectagainstserver
outages,accidentalfilemodificationordeletion,andservers
whosesecurityhavebeencompromised.Bynature,ACVisprotocolindependentandisdesigned
toworkwithanytypeofserverthatcommunicatesviaformattedASCIItextmessages,including
HTTP,FTP,andSM TP.ForACVverification,youspecifythefollowing:
•Astringthat
theroutersendstoasingleserver.ThestringcanbeasimpleHTTPcommandto
getaspecificHTMLpage,oritcanbeacommandtoexecuteauserdefinedCGIscriptthat
teststheoperationoftheapplication.
•Thereplythattheapplicationoneachserversendsis
backusedbytheroutertovalidatethe
content.InthecasewhereaspecificHTMLpageisretrieved,thereplycanbeastringthat
appearsonthepage,suchas“OK”.IfaCGIscriptisexecutedontheserver,itshouldreturna
specificresponse(forexample,
“OK”)thattheroutercanverify.
ACVworksbysendingacommandtoyourserverandsearchingtheresponseforacertainstring.
Ifitfindsthestring,theserverismarkedasUp.Ifthestringisnotfound,theserverismarkedas
Down.
Forexample,ifyousent
thefollowingstringtoyourHTTPserver,“HEAD/HTTP/
1.1\\r\\nHost:www.enterasys.com\\r\\n\\r\\n”,youcould expecttogetaresponseofa
stringreturnedsimilartothefollowing:
HTTP/1.1 200 OK
Date: Tue, 11 Dec 2007 20:03:40 GMT
Server: Apache/2.0.40 (Red Hat Linux)
Last-Modified: Wed, 19 Sep 2007 13:56:03 GMT
ETag: “297bc-b52-65f942c0”
Accept-Ranges: bytes
Content-Length: 2898
Youcansearchforareplystringof“200OK”thiswouldresultinasuccessfulverificationofthe
service.
BecauseACVcansearchforastringinonlythefirst255bytesoftheresponse,inmostHTTPcases
theresponsewillhavetobeinthepacketʹsHTTP
header(i.e.,youwillnotbeabletosearchfora
stringcontainedinthewebpageitself).
SomeprotocolssuchasFTPorSMTPrequireuserstoissueacommandtoclosethesessionafter
makingtherequest.Afaildetectacvquitcommandallowsfortheinputofthequit
string
required.

Table of Contents

Related product manuals