09.03.2013 Views

Brocade_IP_Primer_eBook

Brocade_IP_Primer_eBook

Brocade_IP_Primer_eBook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring FWLB<br />

hash table. If a match exists, it will send the connection to the corresponding<br />

firewall. If it does not exist, the ServerIron selects the receiving firewall, and<br />

updates the hash table with the new entry.<br />

Let's take a look at a more detailed example:<br />

MAC: 0001.2345.6701<br />

<strong>IP</strong>: 123.1.2.1/29<br />

CONSOLE MODEM COMPACT FLASH 1<br />

2<br />

3<br />

4<br />

CONSOLE MODEM COMPACT FLASH 1<br />

2<br />

3<br />

4<br />

TX / RX LINK<br />

TX /RX LINK<br />

TX /RX LINK<br />

TX /RX LINK<br />

TX / RX LINK<br />

TX /RX LINK<br />

TX /RX LINK<br />

TX /RX LINK<br />

HA<br />

Firewall Firewall<br />

10/100<br />

10/100<br />

10/100<br />

10/100<br />

10/100<br />

10/100<br />

10/100<br />

10/100<br />

NetScreen – 204<br />

NetScreen – 204<br />

FW1 FW2<br />

POWER<br />

STATUS-1<br />

ALARM<br />

HA<br />

SESSION<br />

FLASH<br />

<strong>IP</strong>: 192.168.1.1/29<br />

MAC: 0001.2345.6702<br />

BI<br />

4XG<br />

BI24C<br />

T X RX T X RX T X RX T X RX<br />

BI<br />

4XG<br />

BI24C<br />

T X RX T X RX T X RX T X RX<br />

BI24C<br />

6 12 18 24<br />

30 36 42 48<br />

BI24C<br />

BigIron RX-8<br />

NETWORKS<br />

1 7 13 19<br />

25 31 37 43<br />

BI24C<br />

BI24C<br />

BI<br />

BI24C<br />

4XG<br />

T X RX T X RX T X RX T X RX<br />

BI<br />

BI24C<br />

4XG<br />

T X RX T X RX T X RX T X RX<br />

AC OK DC OK ALM<br />

EJECT SYS AC OK DC OK ALM<br />

EJECT SYS AC OK DC OK ALM<br />

EJECT SYS AC OK DC OK ALM<br />

We've defined FW1 and FW2. We've defined them as members of fw-group 2.<br />

Now, we need to define paths. On SI-Outside, we need to define two paths (one<br />

through FW1 and one through FW2) to get to SI-Inside. Likewise, on SI-Inside,<br />

we need to define two paths (one through FW1 and one through FW2) to get to<br />

SI-Outside. Let's configure:<br />

SLB-SI-Outside#conf t<br />

SLB-SI-Outside(config)#server fw-group 2<br />

SLB-SI-Outside(config-tc-2)#fwall-info 1 3 192.168.1.3<br />

123.1.2.1<br />

SLB-SI-Outside(config-tc-2)#fwall-info 2 7 192.168.1.3<br />

123.1.2.2<br />

The syntax of the “fwall-info” command is:<br />

EJECT SYS<br />

SI-Outside<br />

ServerIron<br />

e3 e7<br />

<strong>IP</strong>: 123.1.2.3/29<br />

e2<br />

<strong>IP</strong>: 192.168.1.3/29<br />

SI-Inside<br />

ServerIron<br />

e3 e4<br />

BI<br />

4XG<br />

BI24C<br />

T X RX T X RX T X RX T X RX<br />

BI<br />

4XG<br />

BI24C<br />

T X RX T X RX T X RX T X RX<br />

BI24C<br />

6 12 18 24<br />

30 36 42 48<br />

BI24C<br />

BigIron RX-8<br />

NETWORKS<br />

1 7 13 19<br />

25 31 37 43<br />

BI24C<br />

BI24C<br />

BI<br />

BI24C<br />

4XG<br />

T X RX T X RX T X RX T X RX<br />

BI<br />

BI24C<br />

4XG<br />

T X RX T X RX T X RX T X RX<br />

AC OK DC OK ALM<br />

EJECT SYS AC OK DC OK ALM<br />

EJECT SYS AC OK DC OK ALM<br />

EJECT SYS AC OK DC OK ALM<br />

fwall-info <br />

<br />

The first number is the path number. You will start with one, and move consecutively<br />

through (no gaps) the numbers until reaching 32. The next number is<br />

the outgoing interface number. In the first path, the interface facing FW1 is e<br />

3. The interface facing FW2 is e 7 (as noted in the second path). The first <strong>IP</strong><br />

address is the <strong>IP</strong> address of the opposite ServerIron. Since we're on SI-Outside,<br />

we want to reach the <strong>IP</strong> address of SI-Inside. Finally, we tell it the next<br />

hop <strong>IP</strong> address to get there. In this example, the first path directs SI-Outside<br />

through interface e 1 to 123.1.2.1 (FW1). The second path directs SI-Outside<br />

through interface e 2 to 123.1.2.2 (FW2).<br />

<strong>Brocade</strong> <strong>IP</strong> <strong>Primer</strong> 377<br />

POWER<br />

STATUS-1<br />

ALARM<br />

SESSION<br />

FLASH<br />

e5<br />

EJECT SYS<br />

MAC: 1234.5678.9A01<br />

<strong>IP</strong>: 123.1.2.2/29<br />

<strong>IP</strong>: 192.168.1.2/29<br />

MAC: 1234.5678.9A02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!