Configuring Routing on Servers
The way you configure routing on servers behind Equalizer depends largely on whether Equalizer’s
spoof
option is enabled on a cluster.
Spoof Controls SNAT
If
spoof
is
disabled
, SNAT (Source Network Address Translation) is performed on client requests
before sending them on to the server -- the source address used in the packet sent to the server is
Equalizer’s IP address on the VLAN used to communicate with the server.
If
spoof
is
enabled
, SNAT is
not
performed on client requests before sending them on to the server
-- the source address used in the packet sent to the server is the
client’s
IP address.
How Spoof Influences Routing
When
spoof
is
disabled
, special routing is usually not required on servers, since they will respond
to Equalizer’s IP address on the appropriate VLAN.
When
spoof
is
enabled
, you should configure your servers so that Equalizer gateways the packets
the servers send to clients. If you do not adjust the routing on your servers when the
spoof
option
is enabled, servers will not route responses through Equalizer and clients receiving such
responses directly from servers will drop the responses and the client connection will time out. An
easy way to do this is to configure the server's default gateway to be an address on an Equalizer
subnet. If this is not possible, then static routes should be used to properly route client requests
back to Equalizer.
Direct Server Return (DSR) configurations with Layer 4 clusters are an exception to this rule. In
DSR configurations, client requests coming through Equalizer are routed to servers, which then
respond directly back to the clients without going through Equalizer. Therefore, servers in a DSR
configuration typically have a default gateway other than Equalizer.
In non-DSR clusters with
spoof
enabled, you should use one of the following Equalizer addresses
as the default gateway on the server (for the server instance on the server pool in the cluster):
l
If the servers are connected to a single (standalone) Equalizer
, the default gate-
way IP address that you should use on the server is Equalizer’s IP address on the VLAN asso-
ciated with the Equalizer front-panel port to which the server is connected.
l
If the servers are connected to two Equalizers in a failover configuration
, the
default gateway IP address that you should use on the server is always Equalizer’s failover
IP address on the VLAN associated with the Equalizer front-panel port to which the server is
connected.
The commands or utilities that you use to configure routing on a server depends on the server’s
operating system, but usually involves some form of the route command. Check your server
operating system documentation. To verify that you have configured a server’s routing correctly,
trace the route from the server to a destination address outside the internal network to ensure
that Equalizer gets used as a gateway. On UNIX systems, use
the
traceroute utility; on Windows,
use tracert
.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
469
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......