Working with Clusters and Match Rules
Selective SNAT Example
The procedure below shows you how to create a match rule that selectively disables the cluster
Spoof
option based on the client IP address of an incoming connection. It is assumed that the
cluster for which the match rule is created has
Spoof
enabled
on the cluster
Configuration
screen
(tab), and that the cluster works properly for clients on subnets other than the subnet to which the
server pools in the cluster are connected.
1. Right-click the name of the cluster for which you want to implement selective SNAT, and
select
Add Match Rule
.
2. On the
Add New Match Rule
form:
a. Type in a
Match Name
or accept the default.
b. Select the
Next Match Rule
from the drop down list to place the new match rule
in the desired order on the cluster.
c. Click on
Commit
.
The new match rule is created and its
Configuration
Screen (tab) is opened.
3. Leave
any()
in the
expression
field.
4. In the
Expression Editor
:
a. Drag and drop the
client_ip
function from the
Functions
pane to the
Expression
Workbench
.
b. Specify a simple IP address (e.g., “192.168.0.240”), or an IP address in Class-
less Inter- Domain Routing (CIDR) notation (e.g., “192.168.0.0/24”) to specify
an entire subnet in the
client_ip
function. Click on the
Continue
button when fin-
ished.
The
Expression
field should now contain the
client_ip
function with the
ip
argument you specified
above.
5. Uncheck both the
Spoof
checkbox and the
Disable
checkbox on the
Configuration
Screen
(tab).
6. Click on
Commit
.
Clients whose IP addresses are selected by the new match rule should now be able to connect
successfully to the cluster IP. Right-click the name of the match rule in the left frame; the
Processed
counter in the popup menu should increase as clients are selected by the match rule.
Select
Match Rule Plots
from the popup menu to display a history of the number of connections
processed by the match rule.
Server Selection Based on Content Type Using Match Rules
In this example, assume a configuration that has dedicated one or more server pools to return
only image files (
.gif
,
.jpg
, etc.), while the remainder of the server pools return all the other
content for client requests.
416
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......