D-Link DFL-800-AV-12 User Manual - Page 285

SLB_SAT Rules, rule would also be used

Page 285 highlights

10.3.6. SLB_SAT Rules Chapter 10. Traffic Management The key component in setting up SLB is the SLB_SAT rule in the IP rule set. The steps that should be followed are: 1. Define an Object for each server for which SLB is to be done. 2. Define a Group which included all these objects 3. Define an SLB_SAT Rule in the IP rule set which refers to this Group and where all other SLB parameters are defined. 4. Define a further rule that duplicates the source/destination interface/network of the SLB_SAT rule that allows traffic through. The could be one or combination of • ForwardFast • Allow • NAT The table below shows the rules that would be defined for a typical scenario of a set of webservers behind a D-Link Firewall for which the load is being balanced. The ALLOW rule allows external clients to access the webservers. Rule Name Rule Type WEB_SLB SLB_SAT WEB_SLB_ALW ALLOW Src. Interface any any Src. Network all-nets all-nets Dest. Interface core core Dest. Network ip_ext ip_ext If there are clients on the same network as the webservers that also need access to those webservers then an NAT rule would also be used: Rule Name Rule Type WEB_SLB SLB_SAT WEB_SLB_NAT NAT WEB_SLB_ALW ALLOW Src. Interface any lan any Src. Network all-nets lannet all-nets Dest. Interface core core core Dest. Network ip_ext ip_ext ip_ext Note that the destination interface is specified as core, meaning NetDefendOS itself deals with this. The key advantage of having a separate ALLOW rule is that the webservers can log the exact IP address that is generating external requests. Using only a NAT rule, which is possible, means that webservers would see only the IP address of the D-Link Firewall Example 10.3. Setting up SLB In this example server load balancing is to be done between 2 HTTP webservers which are situated behind a D-Link Firewall. The 2 webservers have the private IP addresses 192.168.1.10 and 192.168.1.11 respectively. The default SLB values for monitoring, distribution method and stickiness are used. A NAT rule is used in conjunction with the SLB_SAT rule so that clients behind the firewall can access the webservers. An ALLOW rule is used to allow access by external clients. Web Interface A. Create an Object for each the webservers: 1. Go to Objects > Address Book > Add > IP Address 2. Enter a suitable name, eg. server1 3. Enter the IP Address as 192.168.1.10 285

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355

The key component in setting up SLB is the
SLB_SAT
rule in the IP rule set. The steps that should
be followed are:
1.
Define an Object for each server for which SLB is to be done.
2.
Define a Group which included all these objects
3.
Define an SLB_SAT Rule in the IP rule set which refers to this Group and where all other SLB
parameters are defined.
4.
Define a further rule that duplicates the source/destination interface/network of the SLB_SAT
rule that allows traffic through. The could be one or combination of
ForwardFast
Allow
NAT
The table below shows the rules that would be defined for a typical scenario of a set of webservers
behind a D-Link Firewall for which the load is being balanced. The
ALLOW
rule allows external
clients to access the webservers.
Rule Name
Rule Type
Src. Interface
Src. Network
Dest. Interface
Dest. Network
WEB_SLB
SLB_SAT
any
all-nets
core
ip_ext
WEB_SLB_ALW
ALLOW
any
all-nets
core
ip_ext
If there are clients on the same network as the webservers that also need access to those webservers
then an
NAT
rule would also be used:
Rule Name
Rule Type
Src. Interface
Src. Network
Dest. Interface
Dest. Network
WEB_SLB
SLB_SAT
any
all-nets
core
ip_ext
WEB_SLB_NAT
NAT
lan
lannet
core
ip_ext
WEB_SLB_ALW
ALLOW
any
all-nets
core
ip_ext
Note that the destination interface is specified as
core
, meaning NetDefendOS itself deals with this.
The key advantage of having a separate
ALLOW
rule is that the webservers can log the exact IP
address that is generating external requests. Using only a
NAT
rule, which is possible, means that
webservers would see only the IP address of the D-Link Firewall
Example 10.3. Setting up SLB
In this example server load balancing is to be done between 2 HTTP webservers which are situated behind a
D-Link Firewall. The 2 webservers have the private IP addresses
192.168.1.10
and
192.168.1.11
respectively.
The default SLB values for monitoring, distribution method and stickiness are used.
A NAT rule is used in conjunction with the SLB_SAT rule so that clients behind the firewall can access the
webservers. An
ALLOW
rule is used to allow access by external clients.
Web Interface
A. Create an Object for each the webservers:
1.
Go to
Objects > Address Book > Add > IP Address
2.
Enter a suitable name, eg.
server1
3.
Enter the
IP Address
as
192.168.1.10
10.3.6. SLB_SAT Rules
Chapter 10. Traffic Management
285