複数ファイアウォール環境
マルチファイアウォール環境でのNetScalerの構成
-
ファイアウォールごとにワイルドカードサービスを構成する
-
ワイルドカードサービスごとにモニターを設定する
-
ワイルドカード仮想サーバーを構成して、ファイアウォールに送信されるトラフィックの負荷を分散します。
-
仮想サーバーをMAC書き換えモードで構成する
-
ファイアウォールサービスをワイルドカード仮想サーバーにバインドする
負荷分散機能を有効にする
enable ns feature <featureName>
show ns feature
enable ns feature LoadBalancing
Done
show ns feature
Feature Acronym Status
------- ------- ------
1) Web Logging WL OFF
2) Surge Protection SP ON
3) Load Balancing LB ON
.
.
.
24) NetScaler Push push OFF
Done
-
ナビゲーションペインで、[System] を展開し、[Settings] をクリックします。
-
「基本機能の設定」ダイアログで、「負荷分散」チェックボックスを選択し、「OK」をクリックします。
各ファイアウォールのワイルドカードサービスの設定
add service <name>@ <serverName> <serviceType> <port_number>
add service fw-svc1 10.102.29.5 ANY *
-
[Traffic Management] > [Load Balancing] > [Services] の順に移動します。
-
詳細ペインで、[Add] をクリックします。
-
「サービスの作成」ダイアログ・ボックスで、次に示すように次のパラメータの値を指定します。
-
サービス名—名前
-
サーバー—サーバー名
-* 必須パラメータ -
各サービスのモニターの設定
add lb monitor <monitorName> <type> [-destIP <ip_addr|ipv6_addr|*>] [-transparent (YES | NO )]
bind lb monitor <monitorName> <serviceName>
add monitor monitor-HTTP-1 HTTP -destip 10.10.10.11 -transparent YES
bind monitor monitor-HTTP-1 fw-svc1
add lb monitor <monitorName> <type> [-destIP <ip_addr|ipv6_addr|*>] [-transparent (YES | NO )] [-send <string>] [-recv <string>]
add lb monitor monitor-udp-1 udp-ecv -destip 10.10.10.11 -transparent YES –send "test message" –recv "site_is_up"
-
詳細ペインで、[Add] をクリックします。
-
「モニターの作成」ダイアログ・ボックスで、次に示すように次のパラメータの値を指定します。
-
Name*
-
type*—type
-
接続先IP
-
透明
-* 必須パラメータ -
ファイアウォールに送信されるトラフィックの負荷分散を行うための仮想サーバーの設定
add lb vserver <name>@ <serviceType> <IPAddress> <port_number>
add lb vserver Vserver-LB-1 ANY * *
-
[Traffic Management]>[Load Balancing]>[Virtual Servers]の順に選択します。
-
詳細ペインで、[Add] をクリックします。
仮想サーバーを MAC リライトモードに設定
set lb vserver <name>@ -m <RedirectionMode>
set lb vserver Vserver-LB-1 -m MAC
-
[Traffic Management]>[Load Balancing]>[Virtual Servers]の順に選択します。
-
「詳細設定」タブの「リダイレクトモード」モードで、「開く」をクリックします。
-
[OK] をクリックします。
ファイアウォールサービスの仮想サーバーへのバインディング
bind lb vserver <name>@ <serviceName>
bind lb vserver Vserver-LB-1 Service-HTTP-1
-
[Traffic Management]>[Load Balancing]>[Virtual Servers]の順に選択します。
-
[OK] をクリックします。
NetScalerアプライアンスでのマルチファイアウォールの負荷分散の構成
set lb parameter -vServerSpecificMac <status>
set lb parameter -vServerSpecificMac ENABLED
-
[Traffic Management]>[Load Balancing]>[Virtual Servers]の順に選択します。
-
詳細ペインで、リダイレクションモードを構成する仮想サーバーを選択します (たとえば、負荷分散パラメーターの構成)。
-
[OK] をクリックします。
設定の保存と検証
-
save ns config
-
show vserver
save config
show lb vserver FWLBVIP2
FWLBVIP2 (\*:\*) - ANY Type: ADDRESS
State: UP
Last state change was at Mon Jun 14 07:22:54 2010
Time since last state change: 0 days, 00:00:32.760
Effective State: UP
Client Idle Timeout: 120 sec
Down state flush: ENABLED
Disable Primary Vserver On Down : DISABLED
No. of Bound Services : 2 (Total) 2 (Active)
Configured Method: LEASTCONNECTION
Current Method: Round Robin, Reason: A new service is bound
Mode: MAC
Persistence: NONE
Connection Failover: DISABLED
1) fw-int-svc1 (10.102.29.5: *) - ANY State: UP Weight: 1
2) fw-int-svc2 (10.102.29.9: \*) - ANY State: UP Weight: 1
Done
show service fw-int-svc1
fw-int-svc1 (10.102.29.5:\*) - ANY
State: DOWN
Last state change was at Thu Jul 8 14:44:51 2010
Time since last state change: 0 days, 00:01:50.240
Server Name: 10.102.29.5
Server ID : 0 Monitor Threshold : 0
Max Conn: 0 Max Req: 0 Max Bandwidth: 0 kbits
Use Source IP: NO
Client Keepalive(CKA): NO
Access Down Service: NO
TCP Buffering(TCPB): NO
HTTP Compression(CMP): NO
Idle timeout: Client: 120 sec Server: 120 sec
Client IP: DISABLED
Cacheable: NO
SC: OFF
SP: OFF
Down state flush: ENABLED
1) Monitor Name: monitor-HTTP-1
State: DOWN Weight: 1
Probes: 9 Failed [Total: 9 Current: 9]
Last response: Failure - Time out during TCP connection establishment stage
Response Time: 2000.0 millisec
2) Monitor Name: ping
State: UP Weight: 1
Probes: 3 Failed [Total: 0 Current: 0]
Last response: Success - ICMP echo reply received.
Response Time: 1.275 millisec
Done
-
「 設定を保存 」ダイアログで、「 はい」をクリックします。
-
[Traffic Management]>[Load Balancing]>[Virtual Servers]の順に選択します。
-
[Traffic Management] > [Load Balancing] > [Services] の順に移動します。
マルチファイアウォール環境におけるファイアウォールの負荷分散設定の監視
仮想サーバーの統計情報を表示する
-
名前
-
IPアドレス
-
ポート
-
プロトコル
-
仮想サーバーの状態
-
受け取ったリクエストの割合
-
ヒット率
コマンドラインインターフェイスを使用して仮想サーバーの統計情報を表示するには
stat lb vserver [-detail] [<name>]
>stat lb vserver -detail
Virtual Server(s) Summary
vsvrIP port Protocol State Req/s Hits/s
One * 80 HTTP UP 5/s 0/s
Two * 0 TCP DOWN 0/s 0/s
Three * 2598 TCP DOWN 0/s 0/s
dnsVirtualNS 10.102.29.90 53 DNS DOWN 0/s 0/s
BRVSERV 10.10.1.1 80 HTTP DOWN 0/s 0/s
LBVIP 10.102.29.66 80 HTTP UP 0/s 0/s
Done