Technical data
Firewall Load Balancing Guide
6 - 34 © 2012 Brocade Communications Systems, Inc. May 31, 2012
Zone2-SI-A(config-tc-2)# l2-fwall
Zone2-SI-A(config-tc-2)# exit
Zone2-SI-A(config)# server fw-name fw1 10.10.2.1
Zone2-SI-A(config-rs-fw1)# port http
Zone2-SI-A(config-rs-fw1)# port http no-health-check
Zone2-SI-A(config-rs-fw1)# port ftp
Zone2-SI-A(config-rs-fw1)# port ftp no-health-check
Zone2-SI-A(config-rs-fw1)# port snmp
Zone2-SI-A(config-rs-fw1)# port snmp no-health-check
Zone2-SI-A(config-rs-fw1)# exit
Zone2-SI-A(config)# server fw-name fw2 10.10.2.2
Zone2-SI-A(config-rs-fw2)# port http
Zone2-SI-A(config-rs-fw2)# port http no-health-check
Zone2-SI-A(config-rs-fw2)# port ftp
Zone2-SI-A(config-rs-fw2)# port ftp no-health-check
Zone2-SI-A(config-rs-fw2)# port snmp
Zone2-SI-A(config-rs-fw2)# port snmp no-health-check
Zone2-SI-A(config-rs-fw2)# exit
Zone2-SI-A(config)# server fw-group 2
Zone2-SI-A(config-tc-2)# fw-name fw1
Zone2-SI-A(config-tc-2)# fw-name fw2
Zone2-SI-A(config-tc-2)# sym-priority 255
Zone2-SI-A(config-tc-2)# fwall-info 1 4/1 10.10.1.111 10.10.2.1
Zone2-SI-A(config-tc-2)# fwall-info 2 4/11 10.10.1.111 10.10.2.2
Zone2-SI-A(config-tc-2)# fwall-info 3 4/1 10.10.1.112 10.10.2.1
Zone2-SI-A(config-tc-2)# fwall-info 4 4/11 10.10.1.112 10.10.2.2
Zone2-SI-A(config-tc-2)# fwall-info 5 4/1 10.10.3.111 10.10.2.1
Zone2-SI-A(config-tc-2)# fwall-info 6 4/11 10.10.3.111 10.10.2.2
Zone2-SI-A(config-tc-2)# exit
Zone2-SI-A(config)# server fw-group 2
Zone2-SI-A(config-tc-2)# fw-predictor per-service-least-conn
Zone2-SI-A(config-tc-2)# exit
Zone2-SI-A(config)# access-list 3 permit 10.10.3.0 0.0.0.255
Zone2-SI-A(config)# access-list 3 permit 10.10.6.0 0.0.0.255
Zone2-SI-A(config)# server fw-group 2
Zone2-SI-A(config-tc-2)# fwall-zone zone3 3 3
Zone2-SI-A(config-tc-2)# exit
Zone2-SI-A(config)# server real-name rs1 10.10.8.40
Zone2-SI-A(config-rs-rs1)# port http
Zone2-SI-A(config-rs-rs1)# exit
Zone2-SI-A(config)# server real-name rs1 10.10.8.42
Zone2-SI-A(config-rs-rs2)# port http
Zone2-SI-A(config-rs-rs2)# exit
Zone2-SI-A(config)# server virtual www.rs.com 10.10.8.10
Zone2-SI-A(config-vs-www.rs.com)# port http
Zone2-SI-A(config-vs-www.web.com)# bind http rs1 http rs2 http
Zone2-SI-A(config-vs-www.web.com)# exit
Zone2-SI-A(config)# server fw-slb
Zone2-SI-A(config)# ip l4-policy 1 fw tcp 0 global
Zone2-SI-A(config)# ip l4-policy 2 fw udp 0 global
Zone2-SI-A(config)# write memory
Commands on Zone 2’s Standby ServerIron (Zone2-SI-S)
ServerIron> enable
ServerIron# configure terminal
ServerIron(config)# hostname Zone2-SI-S
Zone2-SI-S(config)# vlan 1
Zone2-SI-S(config-vlan-1)# always-active