Cisco catalyst 6500 series Configuration Note page 147

Content switching module
Hide thumbs Also See for catalyst 6500 series:
Table of Contents

Advertisement

Chapter 11
Configuring Firewall Load Balancing
Command
Step 6
Switch-A(config-module-csm)# vlan 101
server
Step 7
Switch-A(config-slb-vlan-server)# ip
address 100.0.0.25 255.255.255.0
Step 8
Switch-A(config-slb-vlan-server)# alias
100.0.0.20 255.255.255.0
1.
This step provides a target for CSM B to use in making a load-balancing decision.
Configuring Server Farms on CSM A
Note
To configure two server farms on CSM A, perform this task:
Command
Step 1
Switch-A(config)# module csm 5
Step 2
Switch-A(config-module-csm)# serverfarm
FORWARD-SF
Step 3
Switch-A(config-slb-sfarm)# no nat server
Step 4
Switch-A(config-slb-sfarm)# predictor
forward
Step 5
Switch-A(config-slb-sfarm)# exit
Step 6
Switch-A(config-module-csm)# serverfarm
INSEC-SF
Step 7
Switch-A(config-slb-sfarm)# no nat server
Step 8
Switch-A(config-slb-sfarm)# predictor
hash address source 255.255.255.255
Step 9
Switch-A(config-slb-sfarm)# real
100.0.0.3
Step 10
Switch-A(config-slb-real)# inservice
Step 11
Switch-A(config-slb-real)# exit
Step 12
Switch-A(config-slb-sfarm)# real
100.0.0.4
Step 13
Switch-A(config-slb-real)# inservice
OL-4612-01
Firewall 1 and Firewall 2 secure-side IP addresses are configured as real servers in the SEC-SF
server farm associated with CSM B.
Purpose
Specifies VLAN 101 as the VLAN that is being
configured, identifies it as a server VLAN, and
enters VLAN configuration mode.
Specifies an IP address and netmask for VLAN 101.
Specifies an alias IP address and netmask for VLAN
1
101
.
Purpose
Enters multiple module configuration mode and
specifies that CSM A is installed in slot 5.
Creates and names the FORWARD-SF
(actually a forwarding policy) and enters server farm
configuration mode.
Disables the NAT of server IP addresses and port
2
numbers
.
Forwards traffic by adhering to its internal routing
tables rather than a load-balancing algorithm.
Returns to multiple module configuration mode.
Creates and names the INSEC-SF
(which will contain firewalls as real servers) and
enters server farm configuration mode.
Disables the NAT of the server IP address and port
4
number
.
Selects a server using a hash value based on the
source IP address
Identifies Firewall 1 as a real server, assigns an IP
address to its insecure side, and enters real server
configuration submode.
Enables the firewall.
Returns to server farm configuration mode.
Identifies Firewall 2 as a real server, assigns an IP
address to its insecure side, and enters real server
configuration submode.
Enables the firewall.
Catalyst 6500 Series Content Switching Module Configuration Note
Configuring Regular Firewall Load Balancing
1
server farm
3
server farm
5
.
11-19

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6000 series

Table of Contents