Specifications

How Can I Implement LSNAT?
September 8, 2010 Page 3 of 28
ServerandTCP/UDPportverificationcanensurethattheportsusedbyLSNATareoperational.
TCP/UPDportserviceverificationiscapableofdeterminingwhetheraserverisactivebefore
creatingasession.Thisfeatureeliminatesthepointoffailurevulnerabilitybyautomatically
recognizingaserverisdownandtakingitout
oftheLSNATloadbalancingprocess.
SecurityisimprovedsinceonlytheVIPisknown,notthespecificserveraddresses,ensuringthat
onlytheappropriatetrafficgoestotheservers.
LSNATimprovesnetworkperformancebylevelingtrafficovermanysystems.UsingLSNATin
conjunctionwithAggregateLinksremovestheperformancebottleneck
andreliabilityconcernsof
onephysicallinktoaserverbybundlingmultiplelinks,withfailoverifalinkgoesdown.
UtilizingtheIPPolicyandQoSfeaturesoftheSSeriesand NSeriesdeviceswiththeLSNAT
featurefurtherimprovestheperformanceandsecurityofthenetwork.When
tiedwiththeVirtual
RedundantRouterProtocol(VRRP),thenetworkbecomesevenmorereliableandsecure.
Forallthesereasons,LSNATisidealforenterpriseaccountwebservers,applicationservers,or
databaseservers.
How Can I Implement LSNAT?
ToimplementLSNATinyournetwork:
1. Configureoneormoreserverfarmsby:
–Specifyingaserverfarmname
Configuringrealserversasmembersoftheserverfarm
–Specifyingaloadbalancingalgorithmforeachserverfarm
2. Configureeachrealserverby:
Optionallyconfiguringrealserverfaildetectsettings
Optionallylimitingthemaximumnumberof
activeconnectionsforthisrealserver
Optionallyspecifyingaroundrobinweightvalueforthisrealserver
–Enablingtherealserverforservice
3. Configureavirtualserverby:
–Specifyingavirtualservername
Associatingavirtualserverwithaserverfarm
ConfiguringavirtualserverIPaddress(VIP)
Optionallyrestrictingaccesstospecificvirtual
serverclients
Optionallyspecifyingastickytypeandidletimeout
–Enablingthevirtualserverforservice
4. Configureglobalvirtualserversettingsby:
OptionallydefininganonstandardFTPporttobeusedbyvirtualservers
Optionallyallowingallclientstodirectlyaccessallservicesprovidedbyrealservers
5. Managearealserverbyoptionally
clearingloadbalancingconnectionsorstatistics