Specifications

LSNAT Overview
September 8, 2010 Page 8 of 28
Youcansearchforareplystringof“200OK”.Thiswouldresultinasuccessfulverificationofthe
service.
BecauseACVcansearchforastringinonlythefirst255bytesoftheresponse,inmostHTTPcases
theresponsewillhavetobeinthepacketʹsHTTP
header(thatis,youwillnotbeabletosearchfor
astringcontainedinthewebpageitself).
SomeprotocolssuchasFTPorSMTPrequireuserstoissueacommandtoclosethesessionafter
makingtherequest.Afaildetectacvquitcommandallowsfortheinputofthe
quitstring
required.
The Virtual Server
Thevirtualserverfunctionsasapublicfacetotheclientfortherealservertheclientwishesto
access.TheclientaccessestherealserverbydirectingservicerequeststotheVirtualIP(VIP)
addressconfiguredonthevirtualserver.
Beforeenablingavirtualserveryoumustnameit,associate
itwithaserverfarm,andconfigure
theVIP.Optionallyyoucanrestrictaccesstothevirtualservertospecifiedclients,specifythetype
ofsessionpersistence,allowspecifiedclientsdirectaccesstoarealserver,andallowallclientsto
directlyaccessallservicesnotspecificallyaccessedthroughthe
virtualserver.
YoumustconfigureavirtualserverwithaVIPforeachserverfarminyoursystem.ThesameIP
addresscanbeusedfortheVIPofmultiplevirtualserversprovidedadifferentportisspecified
foreachVIP.
Incaseswherethereisonlyoneloadbalancingdecisionmade
forthisclienttovirtualserverforall
TCP/UDPconnections,the“matchsourceportany”bindingmodeallowsServerLoadBalancing
(SLB)connectionsthroughthevirtualservertocreateasinglebindingthatwillmatchanysource
porttheclientusesdestinedtothesamevirtualserverVIPaddressand
UDP/TCPport.Configure
the“matchsourceportany”bindingmodeusingthebindingmatchsourceportcommand.
Configuring Direct Access to Real Servers
WhentheLSNAT routerhasbeenconfiguredwithserverfarms,withrealserversandvirtual
serversconfiguredand“inservice,”therealserversareprotectedfromdirectclientaccessforall
services.
Ifyouwanttoprovidedirectclientaccesstorealserversconfiguredaspartofaserverfarm,there
aretwomechanismsthatcanprovidedirectclientaccess.
Thefirstmechanism,configuredwithinglobalconfigurationmodewiththeipslbrealserver
accessclientcommand,allowsyoutoidentifyspecificclientnetworksthatcansetupconnections
directlytoarealserversIPaddress,aswellascontinuetouse
thevirtualserverIPaddress.
Thesecondmechanism,configuredinglobalconfigurationmodewiththeipslbrealserver
accessunrestrictedcommand,allowsallclientstodirectlyaccessallservicesprovidedbyreal
servers.
The Source NAT Pool
LSNATsupportsNetworkAddressTranslating(NAT)oftheclientIPaddressasdescribedin
Section3.3ofRFC2391.AguidedetailingtheNATfeatureisavailableat:
http://secure.enterasys.com/support/manuals/.
WithastandardLSNATconnection,theclient’sIPaddressispassedthroughtherouter
unNATed.Theconsequenceofthisisthat
therealservermusthavearoutefortheclientIP