Cisco catalyst 6500 series Configuration Note page 139

Content switching module
Hide thumbs Also See for catalyst 6500 series:
Table of Contents

Advertisement

Chapter 11
Configuring Firewall Load Balancing
Command
Step 12
Switch-A(config-slb-sfarm)# real
10.0.102.200
Step 13
Switch-A(config-slb-real)# inservice
1.
FORWARD-SF is actually a route forwarding policy, not an actual server farm, that allows traffic to reach the Internet
(through VLAN 10). It does not contain any real servers.
2.
This step is required when configuring a server farm that contains a forwarding policy rather than real servers.
3.
INSIDE-SF contains the two alias IP addresses of CSM B listed as real servers that allow traffic from the intranet to reach
CSM B.
4.
This step is required when configuring a server farm that contains firewalls.
5.
We recommend that you perform this step when configuring insecure-side firewall interfaces in a server farm.
Configuring Virtual Servers on CSM A
To configure three virtual servers on CSM A, perform this task:
Command
Step 1
Switch-A(config)# module csm 5
Step 2
Switch-A(config-module-csm)# vserver
FORWARD-V101
Step 3
Switch-A(config-slb-vserver)# virtual
0.0.0.0 0.0.0.0 any
Step 4
Switch-A(config-slb-vserver))# vlan 101
Step 5
Switch-A(config-slb-vserver)# serverfarm
FORWARD-SF
Step 6
Switch-A(config-slb-vserver)# inservice
Step 7
Switch-A(config-slb-vserver)# exit
Step 8
Switch-A(config-module-csm)# vserver
FORWARD-V103
Step 9
Switch-A(config-slb-vserver)# virtual
0.0.0.0 0.0.0.0 any
Step 10
Switch-A(config-slb-vserver))# vlan 103
Step 11
Switch-A(config-slb-vserver)# serverfarm
FORWARD-SF
Step 12
Switch-A(config-slb-vserver)# inservice
Step 13
Switch-A(config-slb-vserver)# exit
Step 14
Switch-A(config-module-csm)# vserver
OUTSIDE-VS
OL-4612-01
Purpose
Identifies the alias IP address of CSM B that lies on
the path to Firewall 2 as a real server and enters real
server configuration submode.
Enables the firewall.
Purpose
Enters multiple module configuration mode and
specifies that the CSM A is installed in slot 5.
Specifies FORWARD-V101
that is being configured and enters virtual server
configuration mode.
Specifies a match for any IP address and any
2
protocol
.
Specifies that the virtual server will only accept
traffic arriving on VLAN 101, which is traffic
arriving from the insecure side of the firewalls.
Specifies the server farm for this virtual server
Enables the virtual server.
Returns to multiple module configuration mode.
Specifies FORWARD-V103
that is being configured and enters virtual server
configuration mode.
Specifies a match for any IP address and any
5
protocol
.
Specifies that the virtual server will only accept
traffic arriving on VLAN 103, which is traffic
arriving from the insecure side of the firewalls.
Specifies the server farm for this virtual server
Enables the virtual server.
Returns to multiple module configuration mode.
Specifies OUTSIDE-VS
being configured and enters virtual server
configuration mode.
Catalyst 6500 Series Content Switching Module Configuration Note
Configuring Stealth Firewall Load Balancing
1
as the virtual server
4
as the virtual server
6
as the virtual server that is
3
.
3
.
11-11

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6000 series

Table of Contents