Cisco catalyst 6500 series Configuration Note page 151

Content switching module
Hide thumbs Also See for catalyst 6500 series:
Table of Contents

Advertisement

Chapter 11
Configuring Firewall Load Balancing
Command
Step 13
Switch-B(config-slb-sfarm)# real
200.0.0.3
Step 14
Switch-B(config-slb-real)# inservice
Step 15
Switch-B(config-slb-real)# exit
Step 16
Switch-B(config-slb-sfarm)# real
200.0.0.4
Step 17
Switch-B(config-slb-real)# inservice
1.
GENERIC-SF contains the real servers in the internal server farm.
2.
SEC-SF contains (firewall 1 and firewall 2)–their secure-side IP addresses are configured as real servers in this server farm.
3.
This is a required step when configuring a server farm that contains firewalls.
4.
We recommend this step when configuring secure-side firewall interfaces in a server farm.
Configuring Virtual Servers on CSM B
To configure three virtual servers on CSM B, perform this task:
Command
Step 1
Switch-B(config)# module csm 6
Step 2
Switch-B(config-module-csm)# vserver
GENERIC-VS
Step 3
Switch-B(config-slb-vserver)# virtual
200.0.0.127 tcp 0
Step 4
Switch-B(config-slb-vserver))# vlan 201
Step 5
Switch-B(config-slb-vserver)# serverfarm
GENERIC-SF
Step 6
Switch-B(config-slb-vserver)# inservice
Step 7
Switch-B(config-slb-vserver)# exit
Step 8
Switch-B(config-module-csm)# vserver
SEC-20-VS
Step 9
Switch-B(config-slb-vserver)# virtual
200.0.0.0 255.255.255.0 any
Step 10
Switch-B(config-slb-vserver))# vlan 20
Step 11
Switch-B(config-slb-vserver)# serverfarm
SEC-SF
Step 12
Switch-B(config-slb-vserver)# inservice
Step 13
Switch-B(config-slb-vserver)# exit
OL-4612-01
Purpose
Identifies Firewall 1 as a real server, assigns an IP
address to its insecure side, and enters real server
configuration submode.
Enables the firewall.
Returns to server farm configuration mode.
Identifies Firewall 2 as a real server, assigns an IP
address to its insecure side, and enters real server
configuration submode.
Enables the firewall.
Purpose
Enters multiple module configuration mode and
specifies that CSM B is installed in slot 6.
Specifies GENERIC-VS
being configured and enters virtual server
configuration mode.
Specifies the IP address, protocol (TCP), and port
(0=any) for this virtual server
Specifies that the virtual server will only accept
traffic arriving on VLAN 201, which is traffic
arriving from the secure side of the firewalls.
Specifies the server farm for this virtual server
Enables the virtual server.
Returns to multiple module configuration mode.
Specifies SEC-20-VS
being configured and enters virtual server
configuration mode.
Specifies the IP address, netmask, and protocol (any)
for this virtual server
Specifies that the virtual server will only accept
traffic arriving on VLAN 20, which is traffic arriving
from the internal server farms.
Specifies the server farm for this virtual server
Enables the virtual server.
Returns to multiple module configuration mode.
Catalyst 6500 Series Content Switching Module Configuration Note
Configuring Regular Firewall Load Balancing
1
as the virtual server that is
2
.
4
as the virtual server that is
2
.
3
.
5
.
11-23

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6000 series

Table of Contents