Use case 7: Configure load balancing in DSR mode by using IP Over IP
-
Create a load balancing virtual server. Set the mode to IPTUNNEL and enable sessionless tracking.
-
Create services. Create a service for each back-end application and bind the services to the virtual server.
-
Configure for decapsulation. Configure either a NetScaler appliance or a back-end server to act as a decapsulator.Note:When you use a NetScaler appliance, the decapsulation setup is an IP tunnel between the ADC appliances with the back end doing L2DSR to the real servers.
Configure a load balancing virtual server
To create and configure a load balancing virtual server for IP over IP DSR by using the command line interface
add lb vserver <name> serviceType <serviceType> IPAddress <ip> Port <port> -lbMethod <method> -m <ipTunnelTag> -sessionless [ENABLED | DISABLED]
show lb vserver <name>
add lb vserver Vserver-LB-1 ANY 1.1.1.80 * -lbMethod SourceIPHash -m IPTUNNEL -sessionless ENABLED
To create and configure a load balancing virtual server for IP over IP DSR by using the GUI
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Create a virtual server, and specify Redirection Mode as IP Tunnel Based.
Configure services for IP over IP DSR
To create and configure a service for IP over IP DSR by using the command line interface
add service <serviceName> <serverName> <serviceType> <port> -usip <usip>
add monitor <monitorName> <monitorType> -destip <ip> -iptunnel <iptunnel>
bind service <serviceName> -monitorName <monitorName>
add monitor mon_DSR PING -destip 1.1.1.80 -iptunnel yes
add service svc_DSR01 2.2.2.100 ANY * -usip yes
bind service svc_DSR01 -monitorName mon_DSR
add ns ip 10.0.1.2 255.255.255.252 -vServer DISABLED
add netProfile netProfile_DSR -srcIP 10.0.1.2
add lb monitor mon_DSR PING -LRTM DISABLED -destIP 1.1.1.80 -ipTunnel YES -netProfile netProfile_DSR
To configure a monitor by using the GUI
-
Navigate to Traffic Management > Load Balancing > Monitors.
-
Create a monitor, and select IP Tunnel.
To create and configure a service for IP over IP DSR by using the GUI
-
Navigate to Traffic Management > Load Balancing > Services.
-
Create a service and, in Settings tab, select Use Source IP Address.
To bind a service to a load balancing virtual server by using the command line interface
bind lb vserver <name> <serviceName>
bind lb vserver Vserver-LB-1 Service-DSR-1
To bind a service to a load balancing virtual server by using the GUI
-
Navigate to Traffic Management > Load Balancing > Virtual Servers.
-
Open a virtual server, and click in the Services section to bind a service to the virtual server.
Using the client IP address in the Outer header of tunnel packets
To use a client-source IP address as the source IP address by using the CLI
-
set iptunnelparam -useclientsourceip [YES | NO] -
show iptunnelparam
To use client source IP address as the source IP address by using the GUI
-
Navigate to System > Network.
-
In Settings tab, click IPv4 Tunnel Global Settings.
-
In the Configure IPv4 Tunnel Global Parameters page, select Use Client Source IP check box.
-
Click OK.
To use client source IP address as the source IP address by using the CLI
-
set ip6tunnelparam -useclientsourceip [YES | NO] -
show ip6tunnelparam
To use client source IP address as the source IP address by using the GUI
-
Navigate to System > Network.
-
In Settings tab, click IPv6 Tunnel Global Settings.
-
In the Configure IPv6 Tunnel Global Parameters page, select Use Client Source IP check box.
-
Click OK.
Decapsulation configuration
NetScaler decapsulation
-
The first virtual server receives the encapsulated packet and removes the outer IP encapsulation.
-
The second virtual server has the IP of the original service on the front-end ADC and uses MAC translation to forward the packet towards the back end by using the MAC address of the bound services. This setup is typically known as L2DSR. Ensure to disable ARP on this virtual server.
add service svc_DSR01 2.2.2.80 ANY * -usip YES -useproxyport NO
add lb vserver vip_DSR_ENCAP ANY 1.1.1.80 * -lbMethod SOURCEIPHASH -m IPTUNNEL -sessionless ENABLED
bind lb vserver vip_DSR_ENCAP svc_DSR01
add ipTunnel DSR-IPIP 1.1.1.100 255.255.255.255 *
add service svc_DSR01_01 2.2.2.101 ANY * -usip YES -useproxyport NO
add service svc_DSR01_02 2.2.2.102 ANY * -usip YES -useproxyport NO
add service svc_DSR01_03 2.2.2.103 ANY * -usip YES -useproxyport NO
add lb vserver vs_DSR_DECAP ANY 2.2.2.80 * -lbMethod SOURCEIPHASH -m IPTUNNEL -sessionless ENABLED -netProfile netProf_DSR_MBF_noIP
add ns ip 1.1.1.80 255.255.255.255 -type VIP -arp DISABLED -snmp DISABLED
add lb vserver vs_DSR_Relay ANY 1.1.1.80 * -lbMethod SOURCEIPHASH -m MAC -sessionless ENABLED
bind lb vserver vs_DSR_DECAP svc_DSR01_01
bind lb vserver vs_DSR_DECAP svc_DSR01_02
bind lb vserver vs_DSR_DECAP svc_DSR01_03
bind lb vserver vip_DSR_Relay svc_DSR01_01
bind lb vserver vip_DSR_Relay svc_DSR01_02
bind lb vserver vip_DSR_Relay svc_DSR01_03
add netProfile netProf_DSR_MBF_noIP -MBF ENABLED
add lb monitor mon_DSR_MAC PING -netProfile netProf_DSR_MBF_noIP
bind service svc_DSR01_01 -monitorName mon_DSR_MAC
bind service svc_DSR01_02 -monitorName mon_DSR_MAC
bind service svc_DSR01_03 -monitorName mon_DSR_MAC
sudo ip addr add 1.1.1.80 255.255.255.255 dev lo
sudo sysctl net.ipv4.conf.all.arp_ignore=1
sudo sysctl net.ipv4.conf.all.arp_announce=2
sudo sysctl net.ipv4.conf.eth4.rp_filter=2 (The interface has the external IP with route towards the ADC)
sudo sysctl net.ipv4.conf.all.forwarding=1
sudo ip link set dev lo arp on
Back-end server decapsulation
-
Configure a loop back interface with IP for service IP.
-
Create a tunnel interface.
-
Add a route through tunnel interface.
-
Configure interface settings as required for traffic.
add ns ip 10.0.1.2 255.255.255.252 -vServer DISABLED
add netProfile netProfile_DSR -srcIP 10.0.1.2
add lb monitor mon_DSR PING -LRTM DISABLED -destIP 1.1.1.80 -ipTunnel YES -netProfile netProfile_DSR
add service svc_DSR01 2.2.2.10 ANY * -usip YES -useproxyport NO
bind service svc_DSR01 -monitorName mon_DSR
add service svc_DSR02 2.2.2.11 ANY * -usip YES -useproxyport NO
bind service svc_DSR02 -monitorName mon_DSR
add service svc_DSR03 2.2.2.12 ANY * -usip YES -useproxyport NO
bind service svc_DSR03 -monitorName mon_DSR
add lb vserver vip_DSR_ENCAP ANY 1.1.1.80 * -lbMethod SOURCEIPHASH -m IPTUNNEL -sessionless ENABLED
bind lb vserver vip_DSR_ENCAP svc_DSR01
bind lb vserver vip_DSR_ENCAP svc_DSR02
bind lb vserver vip_DSR_ENCAP svc_DSR03
modprobe ipip
sudo ip addr add 1.1.1.80 255.255.255.255 dev lo
nmcli connection add type ip-tunnel ip-tunnel.mode ipip con-name tun0
ifname tun0 remote 198.51.100.5 local 203.0.113.10
nmcli connection modify tun0 ipv4.addresses '10.0.1.1/30'
nmcli connection up tun0
sudo sysctl net.ipv4.conf.all.arp_ignore=1
sudo sysctl net.ipv4.conf.all.arp_announce=2
sudo sysctl net.ipv4.conf.tun0.rp_filter=2
sudo sysctl net.ipv4.conf.all.forwarding=1
sudo ip link set dev lo arp off