18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 4: Understanding Policy Configuration<br />

IP Filter rule basics<br />

128<br />

Figure 54: “Source port”<br />

NAT IP Filter rule<br />

implementation<br />

internal<br />

A network<br />

172.27.18.9<br />

Requirements<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

Possible connections from workstation<br />

A to application B using “source port<br />

NAT IP Filter rule<br />

Internal IP<br />

172.27.18.9:50<br />

172.27.18.9:50<br />

172.27.18.9:50<br />

172.27.18.9:50<br />

IP aliases<br />

11.80.1.4<br />

11.80.1.5<br />

11.80.1.6<br />

11.80.1.7<br />

11.80.1.1<br />

Please note the following requirements when using NAT to specify the source<br />

port <strong>of</strong> an IP Filter connection.<br />

• This configuration only applies to uni-directional (source -> destination) IP<br />

Filter rules with stateful inspection enabled.<br />

• Use Source Port when specifying the source port in an IP Filter connection.<br />

See “Creating IP Filter rules” on page 228 for more information.<br />

Sharing IP Filter sessions in an HA cluster<br />

pool <strong>of</strong> available<br />

IP addresses<br />

app. B<br />

192.1.1.1<br />

listening on port 50<br />

Source IP Source Port Dest IP Dest Port<br />

11.80.1.4 50 192.1.1.1 50<br />

11.80.1.5 50 192.1.1.1 50<br />

11.80.1.6 50 192.1.1.1 50<br />

11.80.1.7 50 192.1.1.1 50<br />

When IP Filter session sharing is configured for an HA cluster, the processing<br />

(<strong>of</strong>ten primary) <strong>Sidewinder</strong> <strong>G2</strong> sends out multicast messages to notify the other<br />

nodes (such as the secondary or standby) <strong>Sidewinder</strong> <strong>G2</strong> <strong>of</strong> IP Filter session<br />

activity (such as a new session, closed session, or change in session state).<br />

Each time a <strong>Sidewinder</strong> <strong>G2</strong> receives a message, it updates its local session<br />

table accordingly. All sessions received from the primary <strong>Sidewinder</strong> <strong>G2</strong> will<br />

have a status <strong>of</strong> shared on the secondary/standby <strong>Sidewinder</strong> <strong>G2</strong>.<br />

When HA causes a secondary/standby <strong>Sidewinder</strong> <strong>G2</strong> to take over as the<br />

acting primary, the shared sessions on the acting primary become available.<br />

When a packet is received for a session, it will be validated against the rules <strong>of</strong><br />

the processing <strong>Sidewinder</strong> <strong>G2</strong>. The processing <strong>Sidewinder</strong> <strong>G2</strong> will then begin<br />

sending multicast state-change messages.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!