Cisco catalyst 6500 series Configuration Note page 153

Content switching module
Hide thumbs Also See for catalyst 6500 series:
Table of Contents

Advertisement

Chapter 11
Configuring Firewall Load Balancing
Figure 11-8 Reverse-Sticky for Firewalls
Forward connection to VS1
STICKY INSERT "B"
Unknown load
Client
balancer
12.1.1.1
Client
12.1.1.2
Forward connection to VS1
STICKY INSERT "B"
As shown in
This configuration supports forward direction connections (client to server) using any balancing metric.
Note
However, the balancing metric to the firewalls from VS2 must match that of the unknown load balancer,
or the unknown load balancer must stick new buddy connections in a similar manner if client responses
to server initiated traffic are to be sent to the correct firewall.
OL-4612-01
Server connection decision
STICKY "B"
Sticky "B"
Firewalls
Server connection decision
STICKY "B"
Figure
11-8, the reverse-sticky process is as follows:
A client connects to the CSM virtual server, VS1, through a load-balanced firewall. This load
balancing decision is made without interaction with the CSM.
Server 1 creates a connection back to the original client. This connection matches virtual server
VS2. VS2 uses the sticky information inserted by the original VS1 reverse-sticky. The connection
now is forced to the same Firewall 1.
A second client, coming in through a different firewall, connects to the same VS1. Reverse-sticky
creates a new entry into database B for the second client, pointing to Firewall 2. VS1 also performs
a normal sticky to Server 1.
Server 1 creates a connection back to Client 2. The connection matches the connection in VS2. VS2
uses the sticky information inserted by the original VS1 reverse-sticky. This connection is used for
the connection to Firewall 2.
If the server had originated the first connection, the link back to the server would have been inserted
by VS2, and a normal load balancing decision would have generated a connection to one of the
firewalls.
Server initiatied
connection #1 to VS2
LB to Server 1
Match/Insert on "A"
Catalyst 6500
CSM
Sticky "A"
LB to Server 1
Match/Insert on "A"
connection to VS2
Catalyst 6500 Series Content Switching Module Configuration Note
Configuring Reverse-Sticky for Firewalls
Servers
Server 1
Server initiated
11-25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6000 series

Table of Contents