Technical data
Firewall Load Balancing Guide
5 - 22 © 2012 Brocade Communications Systems, Inc. May 31, 2012
SI-ActiveC(config-rs-FW4)# exit
SI-ActiveC(config-rs-FW4)# server fw-group 2
SI-ActiveC(config-tc-2)# l2-fwall
SI-ActiveC(config-tc-2)# sym-priority 250
SI-ActiveC(config-tc-2)# fw-name fw1
SI-ActiveC(config-tc-2)# fw-name fw2
SI-ActiveC(config-tc-2)# fw-name fw3
SI-ActiveC(config-tc-2)# fw-name fw4
SI-ActiveC(config-tc-2)# fwall-info 1 3/1 20.20.1.111 10.10.2.1
SI-ActiveC(config-tc-2)# fwall-info 2 3/2 20.20.1.111 10.10.2.2
SI-ActiveC(config-tc-2)# fwall-info 3 3/3 20.20.1.111 10.10.2.3
SI-ActiveC(config-tc-2)# fwall-info 4 3/4 20.20.1.111 10.10.2.4
SI-ActiveC(config-tc-2)# fwall-info 5 3/1 20.20.8.111 10.10.2.1
SI-ActiveC(config-tc-2)# fwall-info 6 3/2 20.20.8.111 10.10.2.2
SI-ActiveC(config-tc-2)# fwall-info 7 3/3 20.20.8.111 10.10.2.3
SI-ActiveC(config-tc-2)# fwall-info 8 3/4 20.20.8.111 10.10.2.4
SI-ActiveC(config-tc-2)# fwall-info 9 2/1 10.10.2.120 10.10.2.120
SI-ActiveC(config-tc-2)# fw-predictor per-service-least-conn
SI-ActiveC(config-tc-2)# exit
SI-ActiveC(config)# vlan 1 name DEFAULT-VLAN by port
SI-ActiveC(config-vlan-1)# always-active
SI-ActiveC(config-vlan-1)# no spanning-tree
SI-ActiveC(config-vlan-1)# static-mac-address 0004.80ed.17b4 ethernet 3/1 priority 1
router-type
SI-ActiveC(config-vlan-1)# static-mac-address 0004.80f0.4b3c ethernet 3/2 priority 1
router-type
SI-ActiveC(config-vlan-1)# static-mac-address 0004.80ed.1368 ethernet 3/3 priority 1
router-type
SI-ActiveC(config-vlan-1)# static-mac-address 0004.80eb.5294 ethernet 3/4 priority 1
router-type
SI-ActiveC(config-vlan-1)# exit
SI-ActiveC(config)# vlan 999 by port
SI-ActiveC(config-vlan-999)# untagged ethe 2/5 to 2/8
SI-ActiveC(config-vlan-999)# no spanning-tree
SI-ActiveC(config-vlan-999)# exit
SI-ActiveC(config)# hostname Int-SI-C
SI-ActiveC(config)# ip address 10.10.2.222 255.255.255.0
SI-ActiveC(config)# ip default-gateway 10.10.2.120
SI-ActiveC(config)# auto-cam-repaint
SI-ActiveC(config)# pram-write-retry
SI-ActiveC(config)# write mem
SI-ActiveC(config)# reload
SI-ActiveC(config)# end
Internal ServerIron D (Int-SI-D) Configuration
SI-ActiveD(config)# module 1 bi-0-port-wsm2-management-module
SI-ActiveD(config)# module 2 bi-jc-8-port-gig-module
SI-ActiveD(config)# module 3 bi-jc-16-port-gig-copper-module
SI-ActiveD(config)# trunk switch ethe 2/5 to 2/6
SI-ActiveD(config)# server fw-port 2/5
SI-ActiveD(config)# server router-ports ethernet 2/1
SI-ActiveD(config)# server fw-name fw1 10.10.8.1
SI-ActiveD(config-rs-FW1)# other-ip 10.10.2.1
SI-ActiveD(config-rs-FW1)# port http
SI-ActiveD(config-rs-FW1)# port http no-health-check
SI-ActiveD(config-rs-FW1)# port http url "HEAD /"
SI-ActiveD(config-rs-FW1)# exit
SI-ActiveD(config)# server fw-name fw2 10.10.8.2