User guide

- 7 -
Section 2
WebMux Overview
2.1 Key Features
The WebMux is a standalone network appliance designed primarily to load balance IP traffic
to multiple servers. The WebMux includes the following key features.
Improves performance by distributing the traffic for a site or domain among
multiple servers. No one server will be bogged down trying to service a particular
site.
SSL Termination to reduce the cost of multiple certificates. Also, be able to
regulate the minimum acceptable SSL encryption protocol version.
Provides high availability by tracking which servers are functioning properly and
which servers are out of service. If a server unexpectedly goes down, the WebMux
will automatically re-direct the traffic to other servers, or will bring a standby or
backup server online to service the traffic. The WebMux does application level health
check to many network protocols on servers.
Provides Persistent Connections by memorizing the user browser session and the
server session and sending the same user to the same server. This is important for
sites using shopping cart and dynamically generated pages, like BroadVision, ASP
and JSP sites.
Provides fault tolerance. This installation requires two WebMuxes, a primary and a
secondary. The two WebMuxes will automatically sync the configuration datum.
Easy management. It can be managed via a secured web browser session from
anywhere in the world. By using https 128 bit encryption to the management web
console, secure remote management of server farms is truly possible.
Operating System independent. No software or agent to load on the servers. Non-
intrusive load/failure detection and management.
Provides Proxy function. When communication is initiated from behind the
WebMux, the WebMux will substitute its own address for the internal address. This
allows the web servers to initiate communication for services such as credit card
validation and mapping services.
Note This function only works in NAT mode.
Built-in Firewall Protections (layer 4/5 only). Stop possible hacker intrusion into
your network from Internet. All IP addresses and ports are blocked except the farm IP
address. Built-in functions will detect any possible denial of service attack and make
your services always available.
Note This function only works in NAT mode with “act as IP router” set to “no”. See
Administration Setup section 6.3 for details.