![Coyote Point Systems E350GX Скачать руководство пользователя страница 121](http://html.mh-extra.com/html/coyote-point-systems/e350gx/e350gx_installation-and-administration-manual_2674414121.webp)
Working with Virtual Clusters
Equalizer Installation and Administration Guide
121
Adding a Layer 4 Virtual Cluster
To add a new Layer 4 virtual cluster, follow these steps:
1. Log into the Administrative Interface using a login that has
add/del
access for global parameters (see “Logging
In” on page 52).
2. Right click on
Equalizer
(or the configure
Failover Peer Name
for this Equalizer) at the top of the left frame,
and select
Add Cluster
from the menu that appears. The
Add New Cluster
dialog appears.
3. Select
Layer 4 TCP
or
Layer 4 UDP
and then click the
Next
icon
.
4. Enter the following information:
enable unsafe
renegotiation
SSL session renegotiation is disabled by default for HTTPS clusters to
close the security vulnerability described at:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3355
While there is usually no reason to use client-side renegotiation, it is
typically used by some websites to allow different SSL certificates to be
used for different parts of a website. Equalizer only supports this type of
configuration when redirects are used. With redirects, renegotiation
does not occur -- the client starts a new SSL session when redirected to
a different part of the website that requires a new certificate.
If the
allow unsafe renegotiation
option is enabled, all clients will be
permitted to renegotiate SSL session IDs.
Enabling this option is not
recommended by Coyote Point
, since it leaves your configuration open
to session stealing and data injection.
Note that if SSL processing is done in software (as on the E250GX and
E350GX), then newer clients that contain the fix for CVE-2009-3355 will
be able to renegotiate SSL sessions.
no header rewrite
When enabled, forces Equalizer to pass responses from an HTTPS
cluster’s servers without rewriting them. In the typical Equalizer setup,
you configure servers in an HTTPS cluster to listen and respond using
HTTP; Equalizer communicates with the clients using SSL. If a server
sends an HTTP redirect using the Location: header, this URL most likely
will not include the
https:
protocol. Equalizer rewrites responses from
the server so that they are HTTPS. You can direct Equalizer to pass
responses from the server without rewriting them by enabling the
no
header rewrite
flag.
Cluster Name
The logical name for the cluster, or accept Equalizer’s default. Each cluster
must have a unique name that begins with an alphabetical character (for
example,
CPImages)
.
Cluster IP Address
Enter the
ip address
, which is the dotted decimal IP address of the cluster.
The IP address of the cluster is the external address (for example,
199.146.85.0
) with which clients connect to the cluster.
Содержание E350GX
Страница 18: ...Chapter Preface 18 Equalizer Installation and Administration Guide ...
Страница 38: ...Chapter 1 Equalizer Overview 38 Equalizer Installation and Administration Guide ...
Страница 50: ...Chapter 2 Installing and Configuring Equalizer Hardware 50 Equalizer Installation and Administration Guide ...
Страница 62: ...Chapter 3 Using the Administration Interface 62 Equalizer Installation and Administration Guide ...
Страница 80: ...Chapter 4 Equalizer Network Configuration 80 Equalizer Installation and Administration Guide ...
Страница 110: ...Chapter 5 Configuring Equalizer Operation 110 Equalizer Installation and Administration Guide ...
Страница 208: ...Chapter 7 Monitoring Equalizer Operation 208 Equalizer Installation and Administration Guide ...
Страница 240: ...Chapter 8 Using Match Rules 238 Equalizer Installation and Administration Guide ...
Страница 258: ...Chapter 9 Administering GeoClusters 254 Equalizer Installation and Administration Guide Envoy Configuration Worksheet ...
Страница 262: ...Appendix A Server Agent Probes 258 Equalizer Installation and Administration Guide ...
Страница 274: ...Appendix B Timeout Configuration 270 Equalizer Installation and Administration Guide ...
Страница 280: ...Appendix D Regular Expression Format 276 Equalizer Installation and Administration Guide ...
Страница 296: ...Appendix E Using Certificates in HTTPS Clusters 292 Equalizer Installation and Administration Guide ...
Страница 310: ...Appendix F Equalizer VLB 306 Equalizer Installation and Administration Guide ...
Страница 318: ...Appendix G Troubleshooting 314 Equalizer Installation and Administration Guide ...