Technical data

ServerIron ADX Firewall Load Balancing Guide vii
53-1002436-01
DRAFT: BROCADE CONFIDENTIAL
Appendix A Additional Firewall Configurations
In this appendix. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .165
Configuring FWLB for firewalls with active-standby NICs . . . . . . . .165
Configuring for active-standby firewall links. . . . . . . . . . . . . . .167
Customizing path health checks . . . . . . . . . . . . . . . . . . . . . . . . . . .169
Changing the maximum number of Layer 3 path
health-check retries. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .169
Enabling Layer 4 path health checks for FWLB . . . . . . . . . . . .170
Disabling Layer 4 path health checks on individual
firewalls and application ports . . . . . . . . . . . . . . . . . . . . . . . . . 171
FWLB selection algorithms. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
Hashing based on destination TCP or UDP
application port . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
Specifying a list of application ports for use
when hashing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .172
Overriding the global hash values. . . . . . . . . . . . . . . . . . . . . . .172
Configuring weighted load balancing. . . . . . . . . . . . . . . . . . . . . . . .173
Weight. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .173
Assigning weights to firewalls . . . . . . . . . . . . . . . . . . . . . . . . . .173
Denying FWLB for specific applications. . . . . . . . . . . . . . . . . . . . . . 174
Configuration guidelines . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .175
Denying FWLB . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
Configuring failover tolerance in IronClad configurations . . . . . . .177