12.07.2015 Views

BROCADE IP PRIMER

BROCADE IP PRIMER

BROCADE IP PRIMER

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 17: Firewall Load Balancing (FWLB)The State of the firewall server is determined by a Layer 3 (ping) health checkthat the ServerIron performs. Here, the same rules apply as the real server inSLB. The Administrative State can be one of the following:• 0 - disabled• 1 - enabled• 2 - failed• 3 - testing• 4 - suspect• 6 - activeThe other command will help you to verify your configured paths:SLB-ServerIron#show server fw-pathFirewall Server Path InfoNumber of Fwall = 2Target-ip Next-hop-ip Port Path Status Tx Rx State192.168.1.3 123.1.2.1 3 1 1 1 1 0192.168.1.3 123.1.2.2 7 2 1 1 1 0The Status field will show a “0” if the link is down, and a “1” if the link is up.Likewise, the transmit side (Tx) or the receive side (Rx) can be either “0”(down) or “1” (up). The State applies to IronClad FWLB. A State of “3” meansthat the ServerIron at the other end of the path is in standby mode. A State of“5” means that the ServerIron at the other end of the path is in active mode. IfIronClad FWLB is not configured, the State will always be “0.”Fine-Tuning FWLBThere are a few additional commands that you should be aware of. These aresome additional options to help fine-tune FWLB.First, you can control the rate at which the ServerIron hands off connections tothe firewall. If you have a weaker firewall, this will be something that you'll wantto implement to prevent the firewall from being overwhelmed. The command isunique to the firewall server, and is as follows:SLB-ServerIron#conf tSLB-ServerIron(config)#server fw FW1SLB-ServerIron(config-rs-FW1)#max-tcp-conn-rate 1000The “1000” indicates the maximum number of TCP connections per secondthe ServerIron will send to FW1. This value can be any number from 1 to65,535. There is also a max-udp-conn-rate command that works the sameway for UDP traffic.Second, we move on to the Layer 3 health check. By default, the ServerIronchecks the health of the firewall by sending a ping every 400 milliseconds (5times every two seconds). If the ServerIron receives one or more responseswithin 1.2 seconds, the ServerIron deems the path healthy. If it does not get a380 Brocade <strong>IP</strong> Primer

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!