29-7
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 29 Setting General IPSec VPN Parameters
Understanding Load Balancing
Eligible Platforms
A load-balancing cluster can include security appliance models ASA 5510 (with a Plus license) and
Model 5520 and above. You can also include VPN 3000 Series Concentrators in the cluster. While mixed
configurations are possible, administration is generally simpler if the cluster is homogeneous.
Eligible Clients
Load balancing is effective only on remote sessions initiated with the following clients:
•
Cisco AnyConnect VPN Client (Release 2.0 and later)
•
Cisco VPN Client (Release 3.0 and later)
•
Cisco VPN 3002 Hardware Client (Release 3.5 or later)
•
Cisco PIX 501/506E when acting as an Easy VPN client.
Load balancing works with both IPSec clients and WebVPN sessions. All other clients, including
LAN-to-LAN connections, can connect to a security appliance on which load balancing is enabled, but
they cannot participate in load balancing.
VPN Load-Balancing Cluster Configurations
A load-balancing cluster can consist of all ASA Release 7.0(x) security appliances, all ASA Release
7.1(1) security appliances, all VPN 3000 Concentrators, or a mixture of these, subject to the following
restrictions:
•
Load-balancing clusters that consist of all ASA 7.0(x) security appliances, all ASA 7.1(1) security
appliances, or all VPN 3000 Concentrators can run load balancing for a mixture of IPSec and
WebVPN sessions.
•
Load-balancing clusters that consist of a both of ASA 7.0(x) security appliances and VPN 3000
Concentrators can run load balancing for a mixture of IPSec and WebVPN sessions.
•
Load-balancing clusters that include ASA 7.1(1) security appliances and either ASA 7.0(x) or VPN
3000 Concentrators or both can support only IPSec sessions. In such a configuration, however, the
ASA 7.1(1) security appliances might not reach their full IPSec capacity.
“Scenario 1: Mixed Cluster
with No WebVPN Connections” on page 8
, illustrates this situation.
With Release 7.1(1), IPSec and WebVPN sessions count or weigh equally in determining the load that
each device in the cluster carries. This represents a departure from the load balancing calculation for the
ASA Release 7.0(x) software and the VPN 3000 Concentrator, in that these platforms both use a
weighting algorithm that, on some hardware platforms, calculates WebVPN session load differently
from IPSec session load.
The virtual master of the cluster assigns session requests to the members of the cluster. An ASA Release
7.1(1) security appliance regards all sessions, WebVPN or IPSec, as equal and assigns them accordingly.
An ASA Release 7.0(x) security appliance or a VPN 3000 Concentrator performs a weighting
calculation in assigning session loads.
Note
You can configure the number of IPSec and WebVPN sessions to allow, up to the maximum allowed by
your configuration and license. See
Configuring VPN Session Limits, page 29-12
for a description of
how to set these limits.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......