Alteon Application Switch Operating System Application Guide
Load Balancing Special Services
Document ID: RDWR-ALOS-V2900_AG1302
311
Setting Up IDS Servers
Table 27 illustrates how to configure IDS servers, depending on the IDS server type:
IDS Load Balancing Configurations
The examples in this section illustrate IDS load balancing in two different network environments:
•
Example 1: Load Balancing to a Single IDS Group, page 312
—One Alteon is dedicated to load
balancing two IDS servers in a single group, and a second Alteon performs standard server load
balancing.
•
Example 2: Load Balancing to Multiple IDS Groups, page 315
—A single Alteon performs both
IDS load balancing and standard server load balancing. Two IDS groups are configured: IDS
Group 51 is for HTTP traffic only, and IDS Group 52 is for all other traffic.
Table 27: Setting Up IDS Servers
IDS Server
Configuration
Health Check
Type
Port Configuration
Explanation
Stealth mode
(without IP
addresses or
dummy IP
addresses)
Link
•
IDS servers must
directly connect to
separate physical
ports on Alteon.
•
The real server
number of IDS
server must match
the physical port
number (1 to 26)
on Alteon.
To send packets to different IDS servers,
you must connect IDS servers to
separate ports and associate them with
different VLANs and tag the packets
accordingly. Because unmodified frames
are sent to the IDS servers, Alteon does
not use the L2 destination field of the
packet to direct it to the correct IDS
server.
The port or the VLAN tag is used to
identify the destination IDS server.
However, if the ingress packet is already
tagged, you must use different ports for
different IDS servers.
Stealth mode
(without IP
addresses or
dummy IP
addresses)
SNMP
IDS servers need not
be directly connected
to Alteon.The IDS
servers may be
connected to another
switch via an
interswitch link
between it and Alteon.
SNMP health checks
are used to check the
status of a port/VLAN
on the remote device
that is connected to an
IDS server.
To send packets to different IDS servers,
you must connect IDS servers to
separate ports and associate them with
different VLANs. Because unmodified
frames are sent to the IDS servers,
Alteon does not use the L2 destination
field of the packet to direct it to the
correct IDS server.
The VLAN tag is used to identify the
destination IDS server. However, if the
ingress packet is already tagged, you
must use different VLANs for different
IDS servers.
With IP
addresses
ICMP or ARP
IDS servers need not
be directly connected
to Alteon.The IDS
servers may be
connected via an
Alteon or a Layer 2
switch.
The data packet is modified, so that it is
addressed to the IDS servers.
Destination MAC address is changed to
the real server MAC address.