1. The client with IP address 10.10.10.2, sends a packet to a cluster with IP address 10.10.11.21, through a fire-
wall with IP address 10.10.10.254.
2. The firewall forwards the packet out of it's 10.10.11.254 interface
3. The ADC receives the request through the cluster IP 10.10.11.21.
4. The ADC forwards the request to the server (spoofed): with source IP address 10.10.10.2 and destination IP
address 10.10.11.X.
5. The server responds with a source IP address 10.10.11.X and a destination IP address 10.10.10.2 (the client).
6. The response arrives at the ADC. It doesn't matter which interface it enters ; just the IP addresses in step 5.
7. The ADC then needs to send the packet out:
a. With no route present, it will send it direct to 10.10.10.2 since it's attached to the 10net.
b. With a route present on the 10net, the route wouldn't wouldn’t be used because the source address of the
packet is on the 11net.
c. With a route present on the 11net with:
Destination: 10.10.10/24
Route: 10.10.10.254
The packet would be sent from the 10net--In this example, this is not desirable since the packet should take
the same path back to the client as it took from the client. (Otherwise some firewalls will drop the packet).
d. With a route present on the 11net that looks like this:
Destination: 10.10.10/24
Route: 10.10.11.254
The packet would be sent from the 11net, be sent to the firewall's 11net interface, routed to the 10net and
back to the client. This is the same path that the packet took from the client.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
113
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......