12.07.2015 Views

BROCADE IP PRIMER

BROCADE IP PRIMER

BROCADE IP PRIMER

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Stateful FWLBresponse, it will try again three more times (on chassis models; 8 more timeson stackables) before declaring the path down. The retry number is configurablewith the following command:SLB-ServerIron#conf tSLB-ServerIron(config)#server fw-group 2SLB-ServerIron(config-tc-2)#fw-health-check icmp 15The ServerIron will now retry its health check 15 times before declaring a pathdown. This number can be between 3 and 31.Third, if a ServerIron receives incoming traffic, but the firewall it was going toload balance to has already reach its maximum connections, it will adjust itshashing mechanism and select an alternative firewall. You may also instructthe ServerIron to simply drop incoming packets when a firewall has reached itsmaximum connections. This is done with the following command:SLB-ServerIron#conf tSLB-ServerIron(config)#server fw-group 2SLB-ServerIron(config-tc-2)#fw-exceed-max-dropStateful FWLBA ServerIron performs stateful FWLB by creating and using session entries forsource and destination traffic flows and associating each flow with a specificfirewall. When a ServerIron receives a packet that needs to go through a firewall,the ServerIron checks to see whether it has an existing session entry forthe packet in the following manner:• If the ServerIron does not have a session entry with the packet's sourceand destination addresses, the ServerIron creates one. To create the sessionentry, the ServerIron selects the firewall that has the fewest opensessions with the ServerIron and associates the source and destinationaddresses of the packet with that firewall. The ServerIron also sends thesession information to the other ServerIron in the high-availability pair, sothat the other ServerIron does not need to create a new session for thesame traffic flow.• If the ServerIron already has a session entry for the packet, the ServerIronforwards the traffic to the firewall in the session entry. All packets with thesame source and destination addresses are forwarded to the same firewall.Since the ServerIrons in a high-availability pair exchange sessioninformation, the same firewall is used regardless of which ServerIronreceives the traffic to be forwarded.Brocade <strong>IP</strong> Primer 381

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!