Multiple-Firewall Environment
Configuring the NetScaler in a Multiple-Firewall Environment
-
Configure a wildcard service for each firewall
-
Configure a monitor for each wildcard service
-
Configure a wildcard virtual server to load balance the traffic sent to the firewalls
-
Configure the virtual server in MAC rewrite mode
-
Bind firewall services to the wildcard virtual server
Enabling the load balancing feature
enable ns feature <featureName>
show ns feature
enable ns feature LoadBalancing
Done
show ns feature
Feature Acronym Status
------- ------- ------
1) Web Logging WL OFF
2) Surge Protection SP ON
3) Load Balancing LB ON
.
.
.
24) NetScaler Push push OFF
Done
-
In the navigation pane, expand System, and then click Settings.
-
In the Settings pane, under Modes and Features, click Change basic features.
-
In the Configure Basic Features dialog box, select the Load Balancing check box, and then click Ok.
Configuring a wildcard service for each firewall
add service <name>@ <serverName> <serviceType> <port_number>
add service fw-svc1 10.102.29.5 ANY *
-
Navigate to Traffic Management > Load Balancing > Services.
-
In the details pane, click Add.
-
In the Create Services dialog box, specify values for the following parameters as shown:
-
Service Name—name
-
Server—serverName
-* A required parameter -
-
In Protocol, select Any and in Port, select *.
-
Click Create, and then click Close. The service you created appears in the Services pane.
Configuring a monitor for each service
add lb monitor <monitorName> <type> [-destIP <ip_addr|ipv6_addr|*>] [-transparent (YES | NO )]
bind lb monitor <monitorName> <serviceName>
add monitor monitor-HTTP-1 HTTP -destip 10.10.10.11 -transparent YES
bind monitor monitor-HTTP-1 fw-svc1
add lb monitor <monitorName> <type> [-destIP <ip_addr|ipv6_addr|*>] [-transparent (YES | NO )] [-send <string>] [-recv <string>]
add lb monitor monitor-udp-1 udp-ecv -destip 10.10.10.11 -transparent YES –send "test message" –recv "site_is_up"
-
Navigate to Traffic Management > Load Balancing > Monitors.
-
In the details pane, click Add.
-
In the Create Monitor dialog box, specify values for the following parameters as shown:
-
Name*
-
Type*—type
-
Destination IP
-
Transparent
-* A required parameter -
-
Click Create, and then click Close. In the Monitors pane, select the monitor that you just configured and verify that the settings displayed at the bottom of the screen are correct.
Configuring a virtual server to load balance the traffic sent to the firewalls
add lb vserver <name>@ <serviceType> <IPAddress> <port_number>
add lb vserver Vserver-LB-1 ANY * *
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
In the details pane, click Add.
-
In Protocol, select Any, and in IP Address and Port, select *.
-
Click Create, and then click Close. The virtual server you created appears in the Load Balancing Virtual Servers pane.
Configuring the virtual server to MAC rewrite mode
set lb vserver <name>@ -m <RedirectionMode>
set lb vserver Vserver-LB-1 -m MAC
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
In the details pane, select the virtual server for which you want to configure the redirection mode (for example, Vserver-LB1), and then click Open.
-
On the Advanced tab, under the Redirection Mode mode, click Open.
-
Click Ok.
Binding firewall services to the virtual server
bind lb vserver <name>@ <serviceName>
bind lb vserver Vserver-LB-1 Service-HTTP-1
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
In the details pane, select the virtual server for which you want to configure the redirection mode (for example, Vserver-LB1), and then click Open.
-
In the Configure Virtual Server (Load Balancing) dialog box, on the Services tab, select the Active check box next to the service that you want to bind to the virtual server(for example, Service-HTTP-1 ).
-
Click Ok.
Configuring the multiple-firewall load balancing on the NetScaler appliance
set lb parameter -vServerSpecificMac <status>
set lb parameter -vServerSpecificMac ENABLED
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
In the details pane, select the virtual server for which you want to configure the redirection mode (for example, Configure Load Balancing parameters).
-
In the Set Load Balancing Parameters dialog box, select the Virtual Server Specific MAC check box.
-
Click Ok.
Saving and Verifying the Configuration
-
save ns config
-
show vserver
save config
show lb vserver FWLBVIP2
FWLBVIP2 (*:*) - ANY Type: ADDRESS
State: UP
Last state change was at Mon Jun 14 07:22:54 2010
Time since last state change: 0 days, 00:00:32.760
Effective State: UP
Client Idle Timeout: 120 sec
Down state flush: ENABLED
Disable Primary Vserver On Down : DISABLED
No. of Bound Services : 2 (Total) 2 (Active)
Configured Method: LEASTCONNECTION
Current Method: Round Robin, Reason: A new service is bound
Mode: MAC
Persistence: NONE
Connection Failover: DISABLED
1) fw-int-svc1 (10.102.29.5: *) - ANY State: UP Weight: 1
2) fw-int-svc2 (10.102.29.9: *) - ANY State: UP Weight: 1
Done
show service fw-int-svc1
fw-int-svc1 (10.102.29.5:*) - ANY
State: DOWN
Last state change was at Thu Jul 8 14:44:51 2010
Time since last state change: 0 days, 00:01:50.240
Server Name: 10.102.29.5
Server ID : 0 Monitor Threshold : 0
Max Conn: 0 Max Req: 0 Max Bandwidth: 0 kbits
Use Source IP: NO
Client Keepalive(CKA): NO
Access Down Service: NO
TCP Buffering(TCPB): NO
HTTP Compression(CMP): NO
Idle timeout: Client: 120 sec Server: 120 sec
Client IP: DISABLED
Cacheable: NO
SC: OFF
SP: OFF
Down state flush: ENABLED
1) Monitor Name: monitor-HTTP-1
State: DOWN Weight: 1
Probes: 9 Failed [Total: 9 Current: 9]
Last response: Failure - Time out during TCP connection establishment stage
Response Time: 2000.0 millisec
2) Monitor Name: ping
State: UP Weight: 1
Probes: 3 Failed [Total: 0 Current: 0]
Last response: Success - ICMP echo reply received.
Response Time: 1.275 millisec
Done
-
In the details pane, click Save.
-
In the Save Config dialog box, click Yes.
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
In the details pane, select the virtual server that you created in step 5 and verify that the settings displayed in the Details pane are correct.
-
Navigate to Traffic Management > Load Balancing > Services.
-
In the details pane, select the service that you created in step 5 and verify that the settings displayed in the Details pane are correct.
Monitoring a Firewall Load Balancing Setup in a Multiple-Firewall Environment
Viewing the Statistics of a Virtual Server
-
Name
-
IP address
-
Port
-
Protocol
-
State of the virtual server
-
Rate of requests received
-
Rate of hits
To display virtual server statistics by using the command line interface
stat lb vserver [-detail] [<name>]
>stat lb vserver -detail
Virtual Server(s) Summary
vsvrIP port Protocol State Req/s Hits/s
One * 80 HTTP UP 5/s 0/s
Two * 0 TCP DOWN 0/s 0/s
Three * 2598 TCP DOWN 0/s 0/s
dnsVirtualNS 10.102.29.90 53 DNS DOWN 0/s 0/s
BRVSERV 10.10.1.1 80 HTTP DOWN 0/s 0/s
LBVIP 10.102.29.66 80 HTTP UP 0/s 0/s
Done
-
Navigate to Traffic Management > Load Balancing > Virtual Servers > Statistics.
-
If you want to display the statistics for only one virtual server, in the details pane, select the virtual server, and click Statistics.
Viewing the Statistics of a Service
stat service <name>
stat service Service-HTTP-1
-
Navigate to Traffic Management > Load Balancing > Services > Statistics.
-
If you want to display the statistics for only one service, select the service, and click Statistics.