Configuring Regular Firewall Load Balancing; Packet Flow In A Regular Firewall Configuration - Cisco catalyst 6500 series Configuration Note

Content switching module
Hide thumbs Also See for catalyst 6500 series:
Table of Contents

Advertisement

Configuring Regular Firewall Load Balancing

Command
Step 17
Switch-B(config-slb-vserver)# serverfarm
TO-OUTSIDE-SF
Step 18
Switch-B(config-slb-vserver)# inservice
Step 19
Switch-B(config-slb-vserver)# exit
Step 20
Switch-B(config-module-csm)# vserver
TELNET-VS
Step 21
Switch-B(config-slb-vserver)# virtual
10.1.0.200 255.255.255.0 tcp telnet
Step 22
Switch-B(config-slb-vserver)# serverfarm
SERVERS-SF
Step 23
Switch-B(config-slb-vserver)# inservice
1.
2.
3.
4.
5.
6.
Configuring Regular Firewall Load Balancing
This section describes how to configure firewall load balancing for regular firewalls and provides the
following information:

Packet Flow in a Regular Firewall Configuration

In a regular firewall configuration, firewalls connect to two different VLANs and are configured with IP
addresses on the VLANs to which they connect. (See
Catalyst 6500 Series Content Switching Module Configuration Note
11-16
Client matching is only limited by VLAN restrictions.
This server farm is actually a forwarding predictor rather than an actual server farm containing real servers.
FORWARD-VS allows traffic from the Internet to reach the intranet through VLAN 20.
INSIDE-VS allows traffic from the intranet to reach CSM A through Firewall 1 (through VLANs 102 and 101) or
Firewall 2 (through VLANs 104 and 103).
TELNET-VS allows traffic from the Internet to reach Telnet servers in the internal network.
Clients reach the server farm represented by this virtual server through this address.
Packet Flow in a Regular Firewall Configuration, page 11-16
Regular Firewall Configuration Example, page 11-17
Chapter 11
Configuring Firewall Load Balancing
Purpose
Specifies the server farm for this virtual server
(containing the alias IP addresses of CSM A as real
servers and allowing traffic to flow through
Firewalls 1 and 2) and enters real server
configuration submode.
Enables the virtual server.
Returns to multiple module configuration mode.
5
Specifies TELNET-VS
as the virtual server that is
being configured and enters virtual server
configuration mode.
TELNET-VS does not use a VLAN limit;
Note
any source traffic (from firewalls or internal
network) will be load balanced through this
address.
Specifies the IP address, netmask, protocol (TCP),
and port (Telnet) for this virtual server
Specifies the server farm containing real servers for
this virtual server.
Enables the virtual server.
Figure
11-7.)
6
.
OL-4612-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6000 series

Table of Contents