![Radware Alteon Скачать руководство пользователя страница 691](http://html.mh-extra.com/html/radware/alteon/alteon_application-manual_781134691.webp)
Document ID: RDWR-ALOS-V2900_AG1302
691
Chapter 24 – Virtual Private Network Load
Balancing
The Virtual Private Network (VPN) load balancing feature allows Alteon to simultaneously load
balance up to 255 VPN devices. Alteon records from which VPN server a session was initiated and
ensures that traffic returns back to the same VPN server from which the session started.
The following topics are addressed in this chapter:
•
—Describes a VPN network and how VPN load balancing works in Alteon.
•
VPN Load Balancing Configuration, page 693
—Provides step-by-step instructions to configure
VPN load balancing on a four-subnet network with four Alteons and two VPN devices.
Overview
A VPN is a connection that has the appearance and advantages of a dedicated link, but it occurs over
a shared network. Using a technique called tunneling, data packets are transmitted across a routed
network, such as the Internet, in a private tunnel that simulates a point-to-point connection. This
approach enables network traffic from many sources to travel via separate tunnels across the
infrastructure. It also enables traffic from many sources to be differentiated, so that it can be
directed to specific destinations and receive specific levels of service.
VPNs provide the security features of a firewall, network address translation, data encryption, and
authentication and authorization. Since most of the data sent between VPN initiators and
terminators is encrypted, network devices cannot use information inside the packet to make
intelligent routing decisions.
How VPN Load Balancing Works
VPN load balancing requires that all ingress traffic passing through a particular VPN must traverse
the same VPN as it egresses back to the client. Traffic ingressing from the Internet is usually
addressed to the VPNs, with the real destination encrypted inside the datagram. Traffic egressing
the VPNs into the intranet contains the real destination in the clear.
In many VPN/firewall configurations, it may not be possible to use the hash algorithm on the source
and destination address, because the address may be encrypted inside the datagram. Also, the
source and destination IP addresses of the packet may change as the packet traverses from the
dirty-side Alteons to clean-side Alteons, and back.
To support VPN load balancing, Alteon records the state on frames entering Alteon to and from the
VPNs. This session table ensures that the same VPN server handles all the traffic between an inside
host and an outside client for a particular session.
Note:
VPN load balancing is supported for connecting from remote sites to the network behind the
VPN cluster IP address. A connection initiated from clients internal to the VPN gateways is not
supported.
Basic frame flow, from the dirty side of the network to the clean side, is illustrated in
. An external client is accessing an internal server. The VPN devices do
not perform Network Address Translation (NAT).
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...