The Additional Benefits of SLB
Besides from improving performance and scalability, SLB provides a number of other benefits:
•
SLB increases the reliability of network applications by actively monitoring the servers sharing
the load. SLB can detect when a server fails or becomes congested and will not direct any
further requests to that server until it recovers or has less load.
•
SLB can allow network administrators to perform maintenance tasks on servers or applications
without disrupting services. Individual servers can be restarted, upgraded, removed, or replaced,
and new servers and applications can be added or moved without affecting the rest of a server
farm, or taking down applications.
•
The combination of network monitoring and distributed load sharing also provides an extra level
of protection against Denial Of Service (DoS) attacks.
SLB Algorithm Selection
NetDefendOS SLB is implemented through the use of SLB_SAT rules in the IP rule set and these
rules offer administrators a choice of several different algorithms to distribute the load. These
algorithms are described in detail below and allow the tailoring of SLB to best suit the needs of the
network.
Usage Considerations
There are following issues should be considered when deploying SLB:
•
The servers across which the load is to be balanced.
•
The load distribution mode.
•
The SLB algorithm used.
•
The monitoring method.
Each of these topics is discussed further in the sections that follow.
10.4.2. Identifying the Servers
The first step is to identify the servers across which the load is to be balanced. This might be a
server farm which is a cluster of servers set up to work as a single "virtual server". The servers that
are to be treated as a single virtual server by SLB must be specified.
10.4.3. The Load Distribution Mode
No single method of distributing the server load is ideal for all services. Different types of services
have different needs. In the IP rule set the administrator can configure rules for specific services.
SLB will then filter the packet flow according to these rules.
NetDefendOS SLB supports the following distribution modes:
Per-state Distribution
In this mode, SLB records the state of every connection. The
entire session will then be distributed to the same server. This
guarantees reliable data transmission for that session.
IP Address Stickiness
In this mode, all connections from a specific client will be sent
to the same server. This is particularly important for SSL
services such as HTTPS, which require a consistent connection
10.4.2. Identifying the Servers
Chapter 10. Traffic Management
402
Summary of Contents for 800 - DFL 800 - Security Appliance
Page 24: ...1 3 NetDefendOS State Engine Packet Flow Chapter 1 NetDefendOS Overview 24 ...
Page 69: ...2 6 4 Restore to Factory Defaults Chapter 2 Management and Maintenance 69 ...
Page 121: ...3 9 DNS Chapter 3 Fundamentals 121 ...
Page 181: ...4 7 5 Advanced Settings for Transparent Mode Chapter 4 Routing 181 ...
Page 192: ...5 5 IP Pools Chapter 5 DHCP Services 192 ...
Page 282: ...6 7 Blacklisting Hosts and Networks Chapter 6 Security Mechanisms 282 ...
Page 300: ...mechanism 7 3 7 SAT and FwdFast Rules Chapter 7 Address Translation 300 ...
Page 301: ...7 3 7 SAT and FwdFast Rules Chapter 7 Address Translation 301 ...
Page 318: ...8 3 Customizing HTML Pages Chapter 8 User Authentication 318 ...
Page 322: ...ALG 9 1 5 The TLS Alternative for VPN Chapter 9 VPN 322 ...
Page 377: ...Management Interface Failure with VPN Chapter 9 VPN 377 ...
Page 408: ...10 4 6 SLB_SAT Rules Chapter 10 Traffic Management 408 ...
Page 419: ...11 5 HA Advanced Settings Chapter 11 High Availability 419 ...
Page 426: ...12 3 5 Limitations Chapter 12 ZoneDefense 426 ...
Page 449: ...13 9 Miscellaneous Settings Chapter 13 Advanced Settings 449 ...