1. The client with IP address 10.10.10.2, sends a packet to a cluster with IP address 10.10.11.21, through a fire-
wall with IP address 10.10.10.254.
2. The firewall forwards the packet out of it's 10.10.11.254 interface
3. The ADC receives the request through the cluster IP 10.10.11.21.
4. The ADC forwards the request to the server (spoofed): with source IP address 10.10.10.2 and destination IP
address 10.10.11.X.
5. The server responds with a source IP address 10.10.11.X and a destination IP address 10.10.10.2 (the client).
6. The response arrives at the ADC. It doesn't matter which interface it enters ; just the IP addresses in step 5.
7. The ADC then needs to send the packet out:
a. With no route present, it will send it direct to 10.10.10.2 since it's attached to the 10net.
b. With a route present on the 10net, the route wouldn't wouldn’t be used because the source address of the
packet is on the 11net.
c. With a route present on the 11net with:
Destination: 10.10.10/24
Route: 10.10.10.254
The packet would be sent from the 10net--In this example, this is not desirable since the packet should take
the same path back to the client as it took from the client. (Otherwise some firewalls will drop the packet).
d. With a route present on the 11net that looks like this:
Destination: 10.10.10/24
Route: 10.10.11.254
The packet would be sent from the 11net, be sent to the firewall's 11net interface, routed to the 10net and
back to the client. This is the same path that the packet took from the client.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
113
Equalizer Administration Guide
Содержание Equalizer GX Series
Страница 18: ......
Страница 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Страница 42: ......
Страница 52: ......
Страница 64: ......
Страница 72: ......
Страница 76: ......
Страница 123: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 123 Equalizer Administration Guide ...
Страница 228: ......
Страница 238: ......
Страница 411: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 411 Equalizer Administration Guide ...
Страница 459: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 459 Equalizer Administration Guide ...
Страница 476: ......
Страница 492: ......
Страница 530: ......
Страница 614: ......
Страница 626: ......
Страница 638: ......
Страница 678: ......
Страница 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Страница 754: ......
Страница 790: ......
Страница 804: ......
Страница 842: ......
Страница 847: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 847 Equalizer Administration Guide ...
Страница 866: ......