Appendix B Deployment Examples
Use with the CSS
B-10
Cisco 11000 Series Secure Content Accelerator Configuration Guide
78-13124-05
Table B-2
Transparent Sandwich Installation Device Configuration
Upstream CSS Configuration
Secure Content Accelerator
Configuration
Downstream CSS Configuration
•
Create a VLAN for each
Secure Content Accelerator
to be load balanced
•
Create a separate VLAN to
connect to the downstream
CSS to route port 80 traffic
directly
•
Create a service for each
Secure Content Accelerator
with the IP address of the
corresponding circuit
address on the downstream
Secure Content Accelerator;
define the services as type
“transparent-cache”
•
Create a Layer 4 content rule
to balance the Secure
Content Accelerators, using
advanced-balance ssl and
application ssl to assist SSL
v.3 key reuse, in one of the
following ways:
–
Without a VIP: if you do
not specify a VIP, all
port 443 traffic is
forwarded to the Secure
Content Accelerators
–
With a VIP: when you
specify a VIP, any port
443 traffic not destined
to that VIP can be
routed over the VLAN
specified for port 80 and
SSL traffic terminated
on origin servers
•
Export keys and certificates
from any existing secure
servers, if necessary
•
Assign an IP address to each
Secure Content Accelerator
as specified in the CSS
configuration
•
Assign a default route for
each Secure Content
Accelerator using the
upstream CS VLAN circuit
IP address as the gateway
•
Set up one or more logical
secure servers using
QuickStart wizard
(Chapter 3) or configuration
manager (Chapter 4); you
may wish to use TCP service
port 81 as the remoteport
•
Assign a static route for the
VIP to point to the
downstream CSS VLAN
circuit IP address
•
Create a VLAN for each
Secure Content Accelerator
•
Create a VLAN to connect to
the upstream CSS to route
port 80 traffic directly
•
Create services as required
for each server, adding
“keepalive” attributes as
necessary
•
Create a default ECMP route
for each load balanced
Secure Content Accelerator
using the upstream router as
the gateway for each
upstream VLAN
•
Create a default route to the
upstream CSS to allow
non-SSL traffic to bypass
the Secure Content
Accelerator
•
Create Layer 5 rules for the
secure content
•
Create content rules as
required for non-secure
content
Summary of Contents for CSS11501 - 100Mbps Ethernet Load Balancing Device
Page 4: ......
Page 28: ...Figures xxviii Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 05 ...
Page 30: ...Tables xxx Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 05 ...
Page 422: ...Glossary 4 Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 05 ...
Page 432: ...Index 10 Cisco 11000 Series Secure Content Accelerator Configuration Guide 78 13124 04 ...