Configuration Options
Using load balancing to support higher bandwidth in service provider environment
FortiDDoS v3.2 Installation Guide
28-320-183686-20130401
30
•
•
Maintains state information about the traffic flowing through it and ensures that all
traffic between specific IP address source and destination pairs flows through the
same FortiDDoS unit.
•
Performs health checks on all paths through the FortiDDoS devices. If any path is
not operational, the load balancer diverts traffic away from that path, maintaining
connectivity across the FortiDDoS devices.
You can use an external load balancer such as Linux Virtual Server (LVS), Cisco
Content Switching Module (CSM), or Avaya Load Balancing Manager.
Load Balancing allows you to:
• Maximize FortiDDoS productivity.
• Scale FortiDDoS performance.
• Eliminate the FortiDDoS device as a single point of failure.
You must use
Sandwich topology
for Load Balancing using FortiDDoS device.
Sandwich topology
Refer to
. This topology requires a load-balancing device before and after the
FortiDDoS device cluster. This type of design ensures the highest level of security due
to physical separation of the FortiDDoS interfaces across multiple switches.
Each Load Balancer load balances between IP address interfaces of the peer device
behind the FortiDDoS device. For this to work, each FortiDDoS device must reside in a
different VLAN and subnet, and the physical ports connected to the FortiDDoS device
must be on different VLANs as well. In addition, for each VLAN, both load balancers
must be in the same subnet. Each load balancer interface and the FortiDDoS device
connected to it reside in a separate VLAN. This ensures persistency since all the traffic
through a particular FortiDDoS device is contained in the device’s VLAN.
In typical load balancers, there are two hash predictors:
•
Bi-Directional hash
, which requires both load-balancing devices to share a
common hash value that ultimately produces the same route. Accomplish
bi-directional hashing by hashing the source and destination IP address along with
the destination port of the given flow. The load balancers ensure that all packets
belonging to a session pass through the same FortiDDoS device in both directions.
The devices select a FortiDDoS device based on a symmetric hash function of the
source and destination IP addresses. This ensures that packets traveling between
the same source and destination IP addresses traverse the same FortiDDoS device.
•
Uni-Directional hash
produces the route in the same fashion as a bi-directional
hash and also creates a TCP connection table with the reverse flow path defined.
This allows you to match return path traffic against this connection table rather than
being hashed.
Содержание FortiDDoS
Страница 1: ...FortiDDoS v3 2 Installation Guide ...
Страница 37: ......