Specifications
LSNAT Overview
September 8, 2010 Page 8 of 28
Youcansearchforareplystringof“200OK”.Thiswouldresultinasuccessfulverificationofthe
service.
BecauseACVcansearchforastringinonlythefirst255bytesoftheresponse,inmostHTTPcases
theresponsewillhavetobeinthepacketʹsHTTP
header(thatis,youwillnotbeabletosearchfor
astringcontainedinthewebpageitself).
SomeprotocolssuchasFTPorSMTPrequireuserstoissueacommandtoclosethesessionafter
makingtherequest.Afaildetectacv‐quitcommandallowsfortheinputofthe
quitstring
required.
The Virtual Server
Thevirtualserverfunctionsasapublicfacetotheclientfortherealservertheclientwishesto
access.TheclientaccessestherealserverbydirectingservicerequeststotheVirtualIP(VIP)
addressconfiguredonthevirtualserver.
Beforeenablingavirtualserveryoumustnameit,associate
itwithaserverfarm,andconfigure
theVIP.Optionallyyoucanrestrictaccesstothevirtualservertospecifiedclients,specifythetype
ofsessionpersistence,allowspecifiedclientsdirectaccesstoarealserver,andallowallclientsto
directlyaccessallservicesnotspecificallyaccessedthroughthe
virtualserver.
YoumustconfigureavirtualserverwithaVIPforeachserverfarminyoursystem.ThesameIP
addresscanbeusedfortheVIPofmultiplevirtualserversprovidedadifferentportisspecified
foreachVIP.
Incaseswherethereisonlyoneloadbalancingdecisionmade
forthisclienttovirtualserverforall
TCP/UDPconnections,the“matchsource‐portany”bindingmodeallowsServerLoadBalancing
(SLB)connectionsthroughthevirtualservertocreateasinglebindingthatwillmatchanysource
porttheclientusesdestinedtothesamevirtualserverVIPaddressand
UDP/TCPport.Configure
the“matchsource‐portany”bindingmodeusingthebindingmatchsource‐portcommand.
Configuring Direct Access to Real Servers
WhentheLSNAT routerhasbeenconfiguredwithserverfarms,withrealserversandvirtual
serversconfiguredand“inservice,”therealserversareprotectedfromdirectclientaccessforall
services.
Ifyouwanttoprovidedirectclientaccesstorealserversconfiguredaspartofaserverfarm,there
aretwomechanismsthatcanprovidedirectclientaccess.
Thefirstmechanism,configuredwithinglobalconfigurationmodewiththeipslbreal‐server
accessclientcommand,allowsyoutoidentifyspecificclientnetworksthatcansetupconnections
directlytoarealserver’sIPaddress,aswellascontinuetouse
thevirtualserverIPaddress.
Thesecondmechanism,configuredinglobalconfigurationmodewiththeipslbreal‐server
accessunrestrictedcommand,allowsallclientstodirectlyaccessallservicesprovidedbyreal
servers.
The Source NAT Pool
LSNATsupportsNetworkAddressTranslating(NAT)oftheclientIPaddressasdescribedin
Section3.3ofRFC2391.AguidedetailingtheNATfeatureisavailableat:
http://secure.enterasys.com/support/manuals/.
WithastandardLSNATconnection,theclient’sIPaddressispassedthroughtherouter
un‐NATed.Theconsequenceofthisisthat
therealservermusthavearoutefortheclientIP