Riverbed® Steelhead® RiOS® Application Installation and Getting Started Guide 2010-10

Table Of Contents
1-4
Overview
Accelerating WAN Connections
packets that match a specific criteria and forwarding the packets to the
Steelhead Application, the HP 5400zl or 8200zl switch does not take any
further action on the intercepted packets.
Transparent Mode is available only when an Extended Services zl Module is
installed in an HP 5400zl or 8200zl switch. The switch must also be running
software version K.14.58 or above. (See “Update the Switch Software” on page
2-4 in Chapter 2: “Hardware Installation.”)
Because the HP switch is responsible for intercepting traffic, you must con-
figure policies on the switch to specify exactly which packets should be
intercepted. In other words, you must define certain criteria that the switch
can use to select the packets that should be intercepted. When the switch
determines that packets match these criteria, it redirects the packets to the
Steelhead Application.
Transparent Mode Concepts: Zones and Zone Policies. To define the
criteria the HP 5400zl or 8200zl switch will use to select the packets that will
be intercepted, you will configure:
Zones—A zone is a logical group of switch ports. For example, you might
create an internal zone and assign ports B4 to B24 to this zone. The switch
ports you add can be in different VLANs, but each switch port can be in
only one zone.
The switch supports a maximum of ten zones. Two zones —BYPASS and
SWITCH-SELFare created automatically and cannot be deleted. As the
name suggests, the SWITCH-SELF zone applies only to packets sent to or
from the HP 5400zl or 8200zl switch. For example, the HP switch might
receive or send:
Dynamic routing protocol packets such as Open Shortest Path First
(OSPF) or Routing Information Protocol (RIP) packets
Simple Network Management Protocol (SNMP) packets
You cannot add switch ports to SWITCH-SELF zone.
You can add ports to the BYPASS zone. However, you cannot include the
BYPASS zone in a zone policy. Consequently, the HP 5400zl and 8200zl
switch cannot intercept packets sent to and received from the ports
assigned to the BYPASS zone.
You can create up to eight additional zones. For each zone you create, you
should assign the ports that you want the Steelhead Application to handle
in the same way. For example, you may want to create a zone for LAN
traffic and another zone for WAN traffic. Then you would assign employ-
ees’ switch ports to the LAN zone and the firewall’s switch port to the WAN
zone.