Use case 11: Isolating network traffic using listen policies
| Category | Parameters |
|---|---|
| Ethernet protocol | Source MAC address, destination MAC address |
| Network interface | Network ID, receiving throughput, sending throughput, transmission throughput |
| IP protocol | Source IP address, destination IP address |
| IPv6 protocol | Source IPv6 address, destination IPv6 address |
| TCP protocol | Source port, destination port, maximum segment size, payload, and other options |
| UDP protocol | Source port, destination port |
| VLAN | ID |
How network paths are isolated
Traffic within network domain 1
-
A client from VLAN 11 sends a request for a service available from the service pool in VLAN 120.
-
The load balancing virtual server LB-VIP1, which is configured to listen to traffic from VLAN 11, receives the request and forwards the request to VLAN 110. The virtual server in VLAN 110 forwards the request to shadow load balancing virtual server FW-VIP-1.
-
FW-VIP-1, which is configured to listen to traffic from VLAN 110, receives the request and forwards it to VLAN 120.
-
The load balancing virtual server in VLAN 120 load balances the request to one of the physical servers, App11, App12, or App13.
-
The response sent by the physical server returns by the same path to the client in VLAN 11.
Traffic between network domain 1 and network domain 2
-
A client from VLAN 11, which belongs to Network Domain 1, sends a request for a service available from the service pool in VLAN 220, which belongs to the Network Domain 2.
-
In Network Domain 1, the load balancing virtual server LB-VIP1, which is configured to listen to traffic from VLAN 11, receives the request and forwards the request to VLAN 110.
-
Shadow load balancing virtual server FW-VIP-1, which is configured to listen to VLAN 110 traffic destined to any other domain, receives the request and forwards it to firewall virtual server FW-VIP-2 because the request is destined to a physical server in Network Domain 2.
-
In Network Domain 2, FW-VIP-2 forwards the request to VLAN 220.
-
The load balancing virtual server in VLAN 220 load balances the request to one of the physical servers, App21, App22, or App23.
-
The response sent by the physical server returns by the same path through the firewall in Network Domain 2 and then to Network Domain 1 to reach the client in VLAN 11.
Configuration Steps
-
Add listen policy expressions. Each expression specifies a domain to which traffic is destined. You can use the VLAN ID or other parameters to identify the traffic.
-
For each network domain, configure two virtual servers as follows:
-
Create a load balancing virtual server for which you specify a listen policy that identifies the traffic destined for this domain. You can specify the name of an expression created earlier, or you can create an expression while creating the virtual server.
-
Create another load balancing virtual server, referred to as shadow virtual server, for which you specify a listen policy expression that applies to traffic destined for any domain. On this virtual server, set the service type to ANY and the IP address and port to an asterisk (*). Enable MAC-based forwarding on this virtual server.
-
Enable the L2 Connection option on both the virtual servers.Generally, to identify a connection, the NetScaler appliance uses the 4-tuple of client IP address, client port, destination IP address, and destination port. When you enable the L2 Connection option, the Layer 2 parameters of the connection (channel number, MAC address, and VLAN ID) are used in addition to the normal 4-tuple.
-
-
Add services representing the server pools in the domain, and bind them to the virtual server.
-
Configure the firewall for each domain as a service, and bind all the firewall services to the shadow virtual server.
To isolate network traffic by using the command line interface
add policy expression <expressionName> <listenPolicyExpression>
add lb vserver <name> <serviceType> <ip> <port> -l2conn ON -listenPolicy <expressionName>
add lb vserver <name> ANY * * -l2conn ON -m MAC -listenPolicy <expressionName>
add policy expression e110 client.vlan.id==110
add policy expression e210 client.vlan.id==210
add policy expression e310 client.vlan.id==310
add policy expression e11 client.vlan.id==11
add policy expression e22 client.vlan.id==22
add policy expression e33 client.vlan.id==33
add lb vserver LB-VIP1 HTTP 10.1.1.254 80 -persistenceType NONE -listenPolicy e11
-cltTimeout 180 -l2Conn ON
add lb vserver LB-VIP2 HTTP 10.2.2.254 80 -persistenceType NONE - listenPolicy e22
-cltTimeout 180 -l2Conn ON
add lb vserver LB-VIP3 HTTP 10.3.3.254 80 -persistenceType NONE - listenPolicy e33
-cltTimeout 180 -l2Conn ON
add lb vserver FW-VIP-1 ANY * * -persistenceType NONE -lbMethod ROUNDROBIN - listenPolicy e110 -Listenpriority 1 -m MAC -cltTimeout 120
add lb vserver FW-VIP-2 ANY * * -persistenceType NONE -lbMethod ROUNDROBIN - listenPolicy e210 -Listenpriority 2 -m MAC -cltTimeout 120
add lb vserver FW-VIP-3 ANY * * -persistenceType NONE -lbMethod ROUNDROBIN - listenPolicy e310 -Listenpriority 3 -m MAC -cltTimeout 120
add service RD-1 10.1.1.1 ANY * -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED
-usip NO -useproxyport NO -sp ON -cltTimeout 120 -svrTimeout 120 -CKA NO -TCPB NO -CMP NO
add service RD-2 10.2.2.1 ANY * -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED
-usip NO -useproxyport NO -sp ON -cltTimeout 120 -svrTimeout 120 -CKA NO -TCPB NO -CMP NO
add service RD-3 10.3.3.1 ANY * -gslb NONE -maxClient 0 -maxReq 0 -cip DISABLED
-usip NO -useproxyport NO -sp ON -cltTimeout 120 -svrTimeout 120 -CKA NO -TCPB NO -CMP NO
bind lb vserver FW-VIP-1 RD-1
bind lb vserver FW-VIP-2 RD-2
bind lb vserver FW-VIP-3 RD-3
To isolate network traffic by using the configuration utility
-
Add services representing the servers, as described in Creating a Service.
-
Add each firewall as a service:
-
Navigate to Traffic Management > Load Balancing > Services.
-
Create a service, specifying the protocol as ANY, server as firewall's IP address, and port as 80.
-
-
Configure a load balancing virtual server.
-
Configure the shadow load balancing virtual server.
-
For each network domain, repeat steps 3 and 4.
-
From the Load Balancing Virtual Servers pane, open the virtual servers that you created and verify the settings.