Alteon Application Switch Operating System Application Guide
Firewall Load Balancing
668
Document
ID:
RDWR-ALOS-V2900_AG1302
17. Apply and save the configuration changes.
Four-Subnet FWLB
The four-subnet FWLB method is often deployed in large networks that require high availability
solutions. This method uses filtering, static routing, and Virtual Router Redundancy Protocol (VRRP)
to provide a parallel firewall operation between redundant Alteons.
Figure 110 - Four-Subnet FWLB Network Topology, page 668
illustrates one possible network
topology using the four-subnet method:
Figure 110: Four-Subnet FWLB Network Topology
This network is classified as a high availability network because no single component or link failure
can cause network resources to become unavailable. Simple switches and vertical block interswitch
connections are used to provide multiple paths for network failover. However, the interswitch links
may be trunked together with multiple ports for additional protection from failure.
Note:
Other topologies that use internal hubs, or diagonal cross-connections between Alteons and
simple switches are also possible. While such topologies may resolve networking issues in special
circumstances, they can make configuration more complex and can cause restrictions when using
advanced features such as active-active VRRP, free-metric FWLB, or content-intelligent switching.
In the example topology in
Figure 110 - Four-Subnet FWLB Network Topology, page 668
network is divided into four sections:
•
Subnet 1 includes all equipment between the exterior routers and dirty-side Alteons.
•
Subnet 2 includes the dirty-side Alteons with their interswitch link, and dirty-side firewall
interfaces.
•
Subnet 3 includes the clean-side firewall interfaces, and clean-side Alteons with their interswitch
link.
•
Subnet 4 includes all equipment between the clean-side Alteons and their servers.
In this network, external traffic arrives through both routers. Since VRRP is enabled, one of the
dirty-side Alteons acts as the primary and receives all traffic. The dirty-side primary Alteon performs
FWLB similar to basic FWLB—a redirection filter splits traffic into multiple streams which are routed
through the available firewalls to the primary clean-side Alteon.