Dual VLAN/Network
Another typical configuration is to have two networks connected to Equalizer:
1. One for external connectivity (this is where the Equalizerclients and clusters are)
2. One for internal resources (this is where the servers are)
We start with a single-VLAN configuration with no default route (See
97) and add a second network for external connectivity, along with a default route for that
network, as shown below.
eqcli > vlan external untagged_ports 1 vid 2
eqcli: 12000287: Operation successful
eqcli > vlan external subnet net ip 10.0.0.68/24 default_route 10.0.0.254
eqcli: 12000287: Operation successful
The IP Filter configuration is updated as shown below:
Source Routing Table:
10.0.0.0/24:
default
via 10.0.0.254
IP Filter Rules:
IPv4 Rules:
1: pass on interface lo0 all hits: 0 bytes: 0
2: pass on interface wm1 hits: 36 bytes: 1608
From
To
192.168.211.0/24
->
192.168.211.0/24
3: pass on interface wm0 hits: 48 bytes: 2926
From
To
10.0.0.0/24
->
10.0.0.0/24
4: block on interface wm0 hits: 0 bytes: 0
From
To
5: pass on interface wm0 hits: 27 bytes: 4916
From
To
10.0.0.0/24
->
any
6: pass on interface wm0 hits: 0 bytes: 0
From
To
any
->
10.0.0.0/24
7: block all hits: 1 bytes: 328
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
101
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......