Advertisement

Quick Links

Table of Contents······························································································································ i
Packing List···································································································································· iii
Main Components···························································································································· 1
Front View··································································································································· 1
Rear View···································································································································· 2
WebMux™ Overview······················································································································· 3
Key Features ······························································································································· 3
The WebMux™ Family ··············································································································· 5
Network Overview······················································································································· 7
Sample Configurations ···················································································································· 9
Single WebMux™························································································································ 9
Redundant Installation·············································································································· 11
Installation without IP Address Change ··················································································· 13
Configuring the WebMux ·············································································································· 15
Before you Start ························································································································ 15
Hardware Setup --- Collect Information··················································································· 16
Hardware Setup ---Setup the new network ··············································································· 16
Hardware Setup ---Configuration Summary············································································· 17
Initial Configuration······················································································································ 17
NAT Mode Related Configuration ···························································································· 18
Out-of-Path Related Configuration··························································································· 20
NAT and Out-of-Path Common Configuration ········································································· 20
What if I made mistake in my configuration? ··········································································· 23
Management Console ···················································································································· 24
Login ········································································································································· 24
Main Management Console ······································································································ 26
SSL Keys···································································································································· 27
Administration Set Up ··············································································································· 33
Change Browser Login Password: ··························································································· 39
Set Clock: ·································································································································· 41
Upload/Download····················································································································· 43
Add Farm ·································································································································· 44

Table of Contents

i

Advertisement

Table of Contents
loading

Summary of Contents for CAI Networks WebMux 480S

  • Page 1: Table Of Contents

    Table of Contents Table of Contents······························································································································ i Packing List···································································································································· iii Main Components···························································································································· 1 Front View··································································································································· 1 Rear View···································································································································· 2 WebMux™ Overview······················································································································· 3 Key Features ······························································································································· 3 The WebMux™ Family ··············································································································· 5 Network Overview······················································································································· 7 Sample Configurations ···················································································································· 9 Single WebMux™························································································································ 9 Redundant Installation··············································································································...
  • Page 2 Modify Farm ····························································································································· 49 Add Server: ······························································································································· 51 Modify Server···························································································································· 54 Initial setup change Through Browser······················································································ 56 Initial Configuration Worksheets ·································································································· 58 Sample Configuration Worksheets ································································································ 59 Contact Information ······················································································································ 63 FAQs·············································································································································· 64 Regulations···································································································································· 67 Appendix 1 – How to Add A Loopback Adapter············································································ 68 Appendix 2 - How to make route delete reboot persistent·····························································...
  • Page 3: Packing List

    Packing List • One (1) WebMux™ unit • One (1) Power cord • One (1) User Manual • One (1) Warranty registration card...
  • Page 5: Main Components

    Check Mark Button confirms the selection, Cross Button cancels the selection. At any time when the system is running holding down to the Check Mark Button will invoke the configuration menu, where you can change IP addresses and other settings. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 6: Rear View

    This switches the WebMux™ on and off. When in the "off" position, the front panel power switch is disabled. Power Cord Please use the supplied power cord to connect the WebMux™ to the power source. 1U WebMux™ has a 115V/230V AC universal power supply. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 7: Webmux™ Overview

    Non-intrusive load/failure detection and management. • Provides Proxy function. When communication is initiated from behind the WebMux™, the WebMux™ will substitute its own address for the internal address. This allows the web servers to initiate communication for Copyright© 1997-2006 CAI Networks, Inc.
  • Page 8 WebMux™ goes down, and when it returns online. This feature could reduce server room night shift operator costs, or timely repair should the server goes down unexpectedly. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 9: The Webmux™ Family

    Layer 7 URI load directing Layer 7 URI load directing with host name MIME header matching and cookies Layer 7 hashed URI load directing Fault Tolerance: Diskless Design Port aggregation Failover via Ethernet Service aware Server aware Backup server Copyright© 1997-2006 CAI Networks, Inc.
  • Page 10 Heat Production 350BTU/H 550BTU/H 800BTU/H Power and Cooling Requirement 95 – 130VAC or 195-235VAC at 50-60Hz universal input power required. Absolute operating temperature range is 0-40C. Recommended operation ambient temperature should not to exceed 30C. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 11: Network Overview

    The WebMux™ routes traffic between these two networks. Next, a Virtual Farm or multiple farms must be configured on the WebMux™. A virtual farm is a single representation of the servers to the clients. A farm consists Copyright© 1997-2006 CAI Networks, Inc.
  • Page 12 100 times more traffic to be handled by the WebMux™ load balancer. The disadvantage for direct routing is that the firewall protections built-in to the WebMux™ will no longer function. Users then must provide their own firewall for incoming and outgoing traffic. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 13: Sample Configurations

    The WebMux™ Model 480S, 580SG, and 680PG User Guide – Version 7.0.x Sample Configurations Single WebMux™ • This installation requires one WebMux™. • One WebMux™ interface connects to the Router LAN. The other interface connects to the Server LAN. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 14 IP address to communicate out to the Internet on all ports. If you are doing Network Address Translation of the farm address to a non-routable address, then both the farm address and the WebMux™ interface address must be translated to communicate outbound on all ports. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 15: Redundant Installation

    192.168.255.253; the secondary redundant interface IP address is 192.168.255.254. They can not be changed. • Both WebMuxes connect to the Router LAN, and to the Server LAN. Each WebMux™ interface has a unique IP address. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 16 Internet on all ports. Since the WebMux™ doing Network Address Translation of the farm address to a non-routable address, the farm addresses on the WebMux™ interface must communicate outbound on all ports defined in the farms. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 17: Installation Without Ip Address Change

    On the WebMux™, only the server LAN cable is connected, since there is only one network in direct routing mode. The WebMux™ takes at least two IP addresses to work in this mode, server LAN Interface IP address and farm IP address. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 18 However, if you are going to have the WebMux ™ do SSL termination or Layer 7 load balancing, you must set a server LAN gateway IP in the WebMux™ and have the servers’ default gateway point to that IP address. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 19: Configuring The Webmux

    80/443 ports as one single farm, so that same client browsing the site in HTTP mode will be send to the same server for HTTPS requests. In the combined mode, ports 80/443 will be combined into one farm. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 20: Hardware Setup

    If you have a secondary WebMux™, connect the WebMuxes with a cross- over Ethernet cable. • Connect the servers to the Server LAN • Connect the WebMux™(es) to the Server LAN • Connect the WebMux™(es) to the Router LAN (NAT mode only). Copyright© 1997-2006 CAI Networks, Inc.
  • Page 21: Hardware Setup

    This host name is for identification purposes. You may call it webmux1, webmux2, etc. (Trick to enter name Copyright© 1997-2006 CAI Networks, Inc.
  • Page 22: Nat Mode Related Configuration

    FTP farm IP address for passive FTP connection). For redundant setup, secondary WebMux™ uses the same IP address for this entry as the primary one. This address floats between primary and secondary WebMuxes. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 23 This IP address will be the Default Gateway entry for all the servers on the Server LAN. In an installation with two WebMuxes, if a gateway IP address of 10.1.1.1 is used, this address will ‘float’ between the primary and secondary Copyright© 1997-2006 CAI Networks, Inc.
  • Page 24: Out-Of-Path Related Configuration

    Enter Server LAN Gateway IP address (optional): This is an optional configuration that is used only if you are going to do SSL termination or Layer 7 load balancing. NAT and Out-of-Path Common Configuration Enter External Gateway: Copyright© 1997-2006 CAI Networks, Inc.
  • Page 25 However, sometimes a wrong IP address is entered so that no computer can access the browser management console. At that point, clearing the allowed host file will allow any browser to access it. By default, the Copyright© 1997-2006 CAI Networks, Inc.
  • Page 26 User can select Yes at this point, all the changes made will be discarded. By default the answer is NO, all the changes will be saved to internal solid state storage. Changes will take effect after next reboot. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 27: What If I Made Mistake In My Configuration

    “Clr Allowed Hosts” option, save changes and reboot, which will allow all the IP address to access the management console through browser. You can clear the allowed hosts but not reset the password, or change one option and not change the others. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 28: Management Console

    “setup” in “main management console” section). • The following login page will appear. NOTE: In order to use a browser to manage the WebMux™, the browser must be set to accept all cookies. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 29 NOTE: For first time setup, please login as superuser and go to the Administration Setup by clicking the Setup button. It is important to set up the Server Farm Gateway IP address and network mask first. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 30: Main Management Console

    Changes made to the "Farm" and "Server" will take effect immediately. The changes however are not saved permanently to the flash memory until the "Save" button is clicked. Unsaved farm/server settings will be lost during power outage or WebMux™ reboot. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 31: Ssl Keys

    SSL termination, please ignore this section. WebMux™ supports SSL V2, SSL V3, and TLS V1 with RSA key length from 512, 1024, and 2048. RSA key length 1024 also called 128bit strong encryption. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 32 This might be useful, when you only want encrypted traffic reaching to your servers. You can click “manage key1” or “manage key2” to generate keys, copy and paste signed certificates: Copyright© 1997-2006 CAI Networks, Inc.
  • Page 33 “generate a CSR” – Certificate Signing Request. It is the process that you generated a key pair and send the public key to CA for “signing”. Once your public key signed and pasted into the key management Copyright© 1997-2006 CAI Networks, Inc.
  • Page 34 There should be 3 certificates. The one whose identity is your e-mail address is the site certificate. The one whose subject and issue are identical is the CA root. The 3rd one is called intermediate certificate. Please paste your site certificate first, followed by your intermediate certificate. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 35 Please contact us for how to convert your existing keys. Download/Upload This button will allow the user to save and restore the WebMux™ configuration to and from their management workstation. See later chapter for details. Setup Button Copyright© 1997-2006 CAI Networks, Inc.
  • Page 36 WebMux’s protocol checking. Adding the WebMux™ server LAN IP address and server LAN gateway address to the name resolution table will help resolve this problem. Please read the Q&A section for more information. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 37: Administration Set Up

    C allowed host. If this field is left blank, you can access the management software from any IP address. It is recommended to set this up for security reasons. If wrong IP addresses are entered, management console login Copyright© 1997-2006 CAI Networks, Inc.
  • Page 38 INFO STATS LCD display messages NOTICE LOGIN Successful browser login/logout (exludes timeout logout) NOTICE SETUP Significant access and changes to setup and configuration items. NOTICE EVENT Same as pager/mail messages WARNING LOGIN Unsuccessful browser login Copyright© 1997-2006 CAI Networks, Inc.
  • Page 39 For example, if a DoS attack is occurring, the number of connections to the site would be extremely high. Assuming they exceeded the value set for the “connection warning” threshold, the designated numbers would be paged. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 40 WebMux™ through ARP and TCP Connection; however, most Cisco DSL modems will only talk to the WebMux™ through Ping. The change to this verification method will take effect after the WebMux™ has been rebooted. Front Router Connection Verification IP Address Copyright© 1997-2006 CAI Networks, Inc.
  • Page 41 The URL is truncated to 255 bytes (to be a string of at most 256 bytes with a terminating null). The response from the server must fit in 4k, including all non-display tag and headers etc. This custom CGI Copyright© 1997-2006 CAI Networks, Inc.
  • Page 42 Changes to "server gateway address", "server farm network mask", "WebMux™ http control port", and “WebMux™ https control port” requires a reboot for the new configuration to take effect. You can use the Reboot button to reboot the WebMux™ remotely. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 43: Change Browser Login Password

    Enter the new password. This is the password to which the login will be changed. New Password Again Enter the same password as in the previous box. Confirm/Cancel Click Confirm to execute the change. Click Cancel to return to the previous screen WITHOUT changing the password. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 44 The WebMux™ Model 480S, 580SG, and 680PG User Guide – Version 7.0.x Change PIN To protect the WebMux™ from unauthorized changes from front push buttons, a PIN can be entered here to prevent saving any change from the front panel. By default, there is no PIN. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 45: Set Clock

    Day of the Month Enter the day of the month, 1 through 31. Year Enter the year. Enter all 4 digits. Hour Enter the hour of the day. Use the 24 hour clock, or military time. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 46 Confirm/Cancel Click Confirm to execute the date and time change. Click Cancel to return to the previous screen WITHOUT making any date or time changes. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 47: Upload/Download

    WebMux™ with a new unit, you could save the configuration and upload all settings to the WebMux™, so that you do not need to go through step by step configuration (requires both WebMuxes on the same firmware revision). Copyright© 1997-2006 CAI Networks, Inc.
  • Page 48: Add Farm

    For example, if you want to create an http farm for www.yourdomain.com, the farm IP address will be the IP address for www.yourdomain.com from your DNS record. If the IP address of www.yourdomain.com is 205.188.166.10, then the Farm IP address is also Copyright© 1997-2006 CAI Networks, Inc.
  • Page 49 IP address, the old farm has to be deleted and a new one to be created. Port This is the port number for the farm. If you are choosing one of the known services below, you do not have to specify anything in this field. However, if the Copyright© 1997-2006 CAI Networks, Inc.
  • Page 50 Generic no health check (TCP/UDP) User Specify Custom Defined TCP Services 80 or User Specify Custom Defined UDP Services User Specify Custom Defined TCP/UDP Services User Specify Custom Defined Paired HTTP and HTTPS User Specify (TCP) Service Copyright© 1997-2006 CAI Networks, Inc.
  • Page 51 MAX_AGE setting specified in cookie by the servers. When MAX_AGE is not defined, the cookie expire time is 30 minutes. Layer 7 hashed URI load directing does a hash algorithm on the URI string as part of its load balancing mechanism. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 52 Sometimes operators wants to identify the traffic from client was on the HTTP or HTTPS port. By enable the tagging on the SSL terminated HTTP traffic, operator can see in MIME header the differences between originated HTTP traffic or originated HTTPS traffic. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 53: Modify Farm

    The label field can be changed to make it fit better for describing the farm. Change this will not affect how load balancing works. Farm scheduling method: Eight different methods are supported: • Least connections • Least connections - persistent Copyright© 1997-2006 CAI Networks, Inc.
  • Page 54 If you do not want to allow non-encrypted traffic going to server, change the “No” to “Yes”. Delete: Click this button to delete the entire farm. CAUTION: This function also deletes ALL the servers under this farm. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 55: Add Server

    Enter the port number of the server to be added. CAUTION: Like the IP address, once created, the port number cannot be changed. To correct the port number, the old server needs to be deleted and a new one to be created. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 56 NOTE: If the WebMux is in Out-Of-Path mode, please reference to Appendix 1 and 2 about loopback adapter; It is also important to allow the HTTP server to accept traffic on the farm IP address. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 57 NOTE: If you chose Layer 7 URI load directing with cookies as the scheduling method, the match pattern is also compared to the host MIME header. In other words, you can use a host name as a match pattern criterion. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 58: Modify Server

    Although all numbers from 1 to 100 will allow traffic to go through, using a smaller weight number in each server will have the best load distributing result. Running state: Copyright© 1997-2006 CAI Networks, Inc.
  • Page 59 The WebMux™ Model 480S, 580SG, and 680PG User Guide – Version 7.0.x • Active • Favorite Active • Standby • Last Resort Standby Copyright© 1997-2006 CAI Networks, Inc.
  • Page 60: Initial Setup Change Through Browser

    8 hours, the manager will not be able to login in to the WebMux™. This section on the “rec” screen will allow the manager to correct the clock, if it is off. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 61 The user may change it based on new information obtained from ISP or network engineers. Once you press on the submit button, the WebMux™ will save all the changes to its internal solid state storage and reboot itself with the new value. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 62: Initial Configuration Worksheets

    Server LAN Network IP Address Server LAN Network Broadcast Address Administration Setup Information External Gateway Address Remake /home/WebMux™/conf/passwd Administration HTTP Port Number Secure Administration HTTP Port # Is this WebMux™ primary WebMux™ running solo without backup Reboot? Copyright© 1997-2006 CAI Networks, Inc.
  • Page 63: Sample Configuration Worksheets

    192.168.199.1. Add a farm for 205.133.156.200 and add a server to the farm at 192.168.199.10. You can then add more servers at 192.168.199.20 and 192.168.199.30. You can also add additional farm at 205.133.156.210, above three servers farm. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 64: Redundant Installation

    Server LAN Network Broadcast Address 10.255.255.255 10.255.255.255 Administration Setup Information External gateway IP address 205.133.156.1 205.133.156.1 Remake /home/WebMux™/conf/passwd Administration HTTP Port Number Secure Administration HTTPS Port Is this WebMux™ primary WebMux™ running solo without backup Reboot? Copyright© 1997-2006 CAI Networks, Inc.
  • Page 65 IP.) Administration Setup Information WebMux™ External Gateway IP address 10.1.1.1 Remake /home/WebMux™/conf/passwd Administration HTTP Port Number Secure Administration HTTPS Port Number 35 Is this WebMux™ primary WebMux™ running solo without backup Reboot? Copyright© 1997-2006 CAI Networks, Inc.
  • Page 66 Appendix 2. In the virtual farm, each server uses its original IP address to join the farm. For SSL termination or Layer 7 load balancing, you must set server LAN gateway IP address and set the servers’ default gateway to that IP. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 67: Contact Information

    The WebMux™ Model 480S, 580SG, and 680PG User Guide – Version 7.0.x Contact Information For latest product and support information, please visit our web site at: http://www.cainetworks.com To reach us by e-mail: Support: support@cainetworks.com Sales: sales@cainetworks.com To reach us by phone: Support: 714-550-0901 X2 Copyright© 1997-2006 CAI Networks, Inc.
  • Page 68: Faqs

    In order for wuftp to resolve the IP addresses and stop complaining, place the non-routable IP address entries in the /etc/hosts file on those servers. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 69 In most cases, no. WebMux™ blocks all the incoming traffic from router LAN to your internal network. Unless there is a farm defined for a port number, the outside traffic will not be able to reach to any server Copyright© 1997-2006 CAI Networks, Inc.
  • Page 70 Intel chipsets well. To make them work together, one will need to set the switch to “auto negotiation” on speed, instead of fixed 100. They will communicate each other at 100BT or 1000BT (Pro version only). Copyright© 1997-2006 CAI Networks, Inc.
  • Page 71: Regulations

    Danger of explosion if battery is incorrectly replaced. Replace only with the same or equivalent type recommended by manufacture. Dispose of used Battery according to manufacture instruction and in accordance with your local regulations. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 72: Appendix 1 - How To Add A Loopback Adapter

    “arptables” command to work around: ip addr add farm_ip_addr dev eth0 # add farm IP address on "eth0" arptables -t filter -A IN -d farm_ip_addr -j DROP # keep it from responding to ARP Copyright© 1997-2006 CAI Networks, Inc.
  • Page 73 FARM_IP_ADDR ifconfig lo0:1 FARM_IP_ADDR FARM_IP_ADDR ifconfig lo0:1 netmask 255.255.255.255 ifconfig lo0:1 up For Apple Servers: ifconfig lo0 inet farm_ip_addr netmask 255.255.255.255 alias route delete gateway_ip farm_ip_addr netmask Where lo0 is the loopback adapter. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 74: Appendix 2 - How To Make Route Delete Reboot Persistent

    Please note for Windows 2003 servers, the route for the loopback adapter can not be deleted. However, since Windows 2003 server automatically taking a highest metric number, the route does not need to be deleted. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 75: Appendix 3 - Phone Paging Codes

    - Primary or Secondary cannot reach the other WebMux™ through the serial cable. • 76 - Serial cable communication restored. • 55 - User configuration cannot be parsed by WebMux™ (after the configuration restored through browser). Copyright© 1997-2006 CAI Networks, Inc.
  • Page 76 For WebMux™ Primary Only • 66 - Secondary is not responding. For WebMux™ Secondary Only • 71 - Primary failed. Secondary took over from Primary. • 72 - Primary went back up. Control returns to the Primary. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 77: Appendix 4 - Virtual Hosting Issues

    WebMux™ will excludes that server from serving the farm. If server responses 402, which indicating access is denied for that virtual farm, the WebMux™ will mark that server dead. We have checked with IIS server and Apache server, they both follow the same rules. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 78: Appendix 5 - Sample Custom Cgi Code

    - subtract integer n from the weight WEIGHT+=n - add integer n to the weight The response must be in all capitals to be recognized. The changes in weight count as an unsaved configuration change. It is not automatically saved. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 79: Appendix 6 - Access Cli Commands

    - print the route packets take to network host Most commands can be found on Unix, for detailed usage, please refer to any Unix man pages. Our support center does not support the usage of these commands. Copyright© 1997-2006 CAI Networks, Inc.
  • Page 80: Appendix 7 - Extended Regular Expressions

    Items with either OO or "Object Oriented" or “Object-Oriented” on one line. OO|([oO]bject( |\-)[oO]riented) To search for characters other than letters or digits put a "\" in front of them. S\/SL These examples were taken from the following web page: http://www.csci.csusb.edu/dick/samples/egrep.html Copyright© 1997-2006 CAI Networks, Inc.
  • Page 81: Index

    66, 68, 70 fault tolerance · 3 Firewall · 4, 58, 59, 60, 61 gateway · 10, 12, 14, 19, 20, 21, 28, 32, 35, 38, 59, 60, 62, 65, 66, 69, 71 generate · 28, 29 Copyright© 1997-2006 CAI Networks, Inc.
  • Page 82 Reboot · 17, 23, 38, 58, 59, 60, 61, 68 Round-Robin · 5 route · 14, 21, 36, 45, 62, 68, 70, 75 Router LAN · 2, 7, 9, 10, 11, 12, 16, 18, 19, 58, 59, 60, 65 Copyright© 1997-2006 CAI Networks, Inc.
  • Page 83 Timeout · 32, 37 TLS · 27 Upload · 31, 43 URL · 24, 37, 46, 56, 73 version · 17, 38, 45, 51, 66 Virtual Farm · 7, 15 weight · 38, 52, 54, 64, 74 Copyright© 1997-2006 CAI Networks, Inc.

This manual is also suitable for:

Webmux 580sgWebmux 680pg

Table of Contents