Radware Alteon Application Manual page 748

Application switch operating system
Hide thumbs Also See for Alteon:
Table of Contents

Advertisement

Alteon Application Switch Operating System Application Guide
Global Server Load Balancing
As a result, the following occurs:
1. A new KSK is created and stored in the key storage location.
2. All the relevant keys are signed with the new KSK.
3. The new KSK is published using DNSKEY.
4. The system administrator is notified through SNMP, console, or e-mail that a new KSK has been
created.
5. The KSK rollover is counted to zero.
6. The resource record of the parent points to the new DNSKEY.
7. A timeout of 48 hours, in addition to the TTL of the original KSK, starts.
8. The old DNSKEY is removed.
9. The system administrator is notified through SNMP, console, or e-mail that a new KSK is created
and in place.
Emergency Rollovers
Emergency rollover is an administrator action.
When an emergency KSK rollover is enabled, Alteon waits for the DS record to be signed by the
parent. The timer waits a pre-defined period (KSK Rollover Phase timer). If the administrator does
not ensure that the DS was signed, a warning is issued that the DNSSEC service might be disturbed.
To initiate a ZSK emergency rollover
1. Initiate the emergency rollover.
The system administrator is warned through SNMP, console, or e-mail that an emergency ZSK
rollover has been initiated, which can disrupt services.
2. The system administrator must confirm the emergency rollover.
The system administrator is notified through SNMP, console, or e-mail that a new ZSK has been
created.
3. A new ZSK is created and stored in the key storage location.
4. The new ZSK is signed with the existing ZSK.
5. The new ZSK is published using DNSKEY.
6. All zone records are signed with the new ZSK, including all RRSIGs still existing in cache.
7. The old RRSIGs are removed from storage.
8. The old ZSK are revoked and removed from storage.
9. The system administrator is notified through SNMP, console, or e-mail that the emergency
rollover is complete.
To initiate a KSK emergency rollover
Initiate the emergency rollover. As a result, the following occurs:
1. A new KSK is created and stored in the key storage location.
2. All the relevant keys are signed with the new KSK.
3. The new KSK is published using DNSKEY.
748
Document ID: RDWR-ALOS-V2900_AG1302

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents