Specifications
How Can I Implement LSNAT?
September 8, 2010 Page 3 of 28
ServerandTCP/UDPportverificationcanensurethattheportsusedbyLSNATareoperational.
TCP/UPDportserviceverificationiscapableofdeterminingwhetheraserverisactivebefore
creatingasession.Thisfeatureeliminatesthepointoffailurevulnerabilitybyautomatically
recognizingaserverisdownandtakingitout
oftheLSNATloadbalancingprocess.
SecurityisimprovedsinceonlytheVIPisknown,notthespecificserveraddresses,ensuringthat
onlytheappropriatetrafficgoestotheservers.
LSNATimprovesnetworkperformancebylevelingtrafficovermanysystems.UsingLSNATin
conjunctionwithAggregateLinksremovestheperformancebottleneck
andreliabilityconcernsof
onephysicallinktoaserverbybundlingmultiplelinks,withfailoverifalinkgoesdown.
UtilizingtheIP‐PolicyandQoSfeaturesoftheS‐Seriesand N‐SeriesdeviceswiththeLSNAT
featurefurtherimprovestheperformanceandsecurityofthenetwork.When
tiedwiththeVirtual
RedundantRouterProtocol(VRRP),thenetworkbecomesevenmorereliableandsecure.
Forallthesereasons,LSNATisidealforenterpriseaccountwebservers,applicationservers,or
databaseservers.
How Can I Implement LSNAT?
ToimplementLSNATinyournetwork:
1. Configureoneormoreserverfarmsby:
–Specifyingaserverfarmname
– Configuringrealserversasmembersoftheserverfarm
–Specifyingaloadbalancingalgorithmforeachserverfarm
2. Configureeachrealserverby:
– Optionallyconfiguringrealserverfail‐detectsettings
– Optionallylimitingthemaximumnumberof
activeconnectionsforthisrealserver
– Optionallyspecifyingaroundrobinweightvalueforthisrealserver
–Enablingtherealserverforservice
3. Configureavirtualserverby:
–Specifyingavirtualservername
– Associatingavirtualserverwithaserverfarm
– ConfiguringavirtualserverIPaddress(VIP)
– Optionallyrestrictingaccesstospecificvirtual
serverclients
– Optionallyspecifyingastickytypeandidletimeout
–Enablingthevirtualserverforservice
4. Configureglobalvirtualserversettingsby:
– Optionallydefininganon‐standardFTPporttobeusedbyvirtualservers
– Optionallyallowingallclientstodirectlyaccessallservicesprovidedbyrealservers
5. Managearealserverbyoptionally
clearingloadbalancingconnectionsorstatistics