Technical data
May 31, 2012 © 2012 Brocade Communications Systems, Inc. vii
CHAPTER 10
C
ONFIGURING FWLB FOR LAYER 2 FIREWALLS ........................................ 10-1
CONFIGURING FWLB FOR LAYER 2 FIREWALLS .........................................................................................10-1
C
ONFIGURING A SWITCH TRUNK GROUP FOR THE FIREWALL PORTS ....................................................10-3
S
PECIFYING THE PARTNER PORT ........................................................................................................10-3
S
PECIFYING THE ROUTER PORTS .......................................................................................................10-4
D
EFINING THE FIREWALLS AND ADDING THEM TO THE FIREWALL GROUP .............................................10-4
E
NABLING THE L2-FWALL OPTION .......................................................................................................10-5
C
ONFIGURING PATHS AND ADDING STATIC MAC ENTRIES FOR LAYER 2 FIREWALLS ............................10-5
C
ONFIGURING THE SERVERIRON PRIORITY ..........................................................................................10-8
E
NABLING FWLB ...............................................................................................................................10-8
C
ONFIGURATION EXAMPLE FOR FWLB WITH LAYER 2 FIREWALLS ..............................................................10-9
C
OMMANDS ON ACTIVE SERVERIRON A (EXTERNAL ACTIVE) ...............................................................10-9
C
OMMANDS ON STANDBY SERVERIRON A (EXTERNAL STANDBY) .......................................................10-11
C
OMMANDS ON ACTIVE SERVERIRON B (INTERNAL ACTIVE) ..............................................................10-12
C
OMMANDS ON STANDBY SERVERIRON B (INTERNAL STANDBY) ........................................................10-12
ADDITIONAL FIREWALL CONFIGURATIONS....................................................A-1
CONFIGURING FWLB FOR FIREWALLS WITH ACTIVE-STANDBY NICS ........................................................... A-1
C
ONFIGURING FOR ACTIVE-STANDBY FIREWALL LINKS ......................................................................... A-3
C
OMMANDS FOR ACTIVE EXTERNAL SERVERIRON (SI-EXT-A) ........................................................ A-3
C
OMMANDS FOR STANDBY EXTERNAL SERVERIRON (SI-EXT-S)..................................................... A-3
C
OMMANDS FOR ACTIVE INTERNAL SERVERIRON (SI-INT-A) .......................................................... A-3
C
OMMANDS FOR STANDBY INTERNAL SERVERIRON (SI-INT-S) ....................................................... A-3
C
USTOMIZING PATH HEALTH CHECKS ........................................................................................................ A-4
C
HANGING THE MAXIMUM NUMBER OF LAYER 3 PATH HEALTH-CHECK RETRIES ................................... A-4
E
NABLING LAYER 4 PATH HEALTH CHECKS FOR FWLB ........................................................................ A-5
D
ISABLING LAYER 4 PATH HEALTH CHECKS ON INDIVIDUAL FIREWALLS AND APPLICATION PORTS ......... A-5
FWLB S
ELECTION ALGORITHMS ................................................................................................................ A-6
H
ASHING BASED ON DESTINATION TCP OR UDP APPLICATION PORT ................................................... A-6
S
PECIFYING A LIST OF APPLICATION PORTS FOR USE WHEN HASHING ................................................. A-6
S
PECIFYING A RANGE OF APPLICATION PORTS FOR USE WHEN HASHING ............................................. A-6
O
VERRIDING THE GLOBAL HASH VALUES ............................................................................................. A-7
C
ONFIGURING WEIGHTED LOAD BALANCING ............................................................................................... A-7
W
EIGHT .............................................................................................................................................. A-7
A
SSIGNING WEIGHTS TO FIREWALLS .................................................................................................... A-8
D
ENYING FWLB FOR SPECIFIC APPLICATIONS ............................................................................................ A-8
C
ONFIGURATION GUIDELINES ............................................................................................................ A-10
D
ENYING FWLB ............................................................................................................................... A-10
S
ERVERIRON A COMMANDS ........................................................................................................ A-10
S
ERVERIRON B COMMANDS ........................................................................................................ A-11
C
ONFIGURING FAILOVER TOLERANCE IN IRONCLAD CONFIGURATIONS ....................................................... A-11