![Radware Alteon Скачать руководство пользователя страница 712](http://html.mh-extra.com/html/radware/alteon/alteon_application-manual_781134712.webp)
Alteon Application Switch Operating System Application Guide
Global Server Load Balancing
712
Document
ID:
RDWR-ALOS-V2900_AG1302
To set client proximity parameters
To view the client proximity statistics
GSLB Persistence Metric
When Alteon receives a GSLB client request that includes a rule with the persistence metric, it
searches the relevant server persistency cache for the client IP address and subnet mask.
If Alteon finds the client IP address and mask, it executes the rule. If Alteon does not find the client
IP address and mask, it returns a saved GSLB load-balancing decision from the persistence table
and stops the process.
To enable GSLB persistence
GSLB and DNSSEC
The Domain Name System Security Extensions (DNSSEC) adds authentication security
measurements to Alteon to defend the DNS protocol against known DNS threats. DNS digitally signs
records for DNS lookup using public-key cryptography. The correct DNSKEY record is authenticated
using a chain of trust, starting with a set of verified public keys for the DNS root zone, which is the
trusted third party. When DNSSEC is used, each answer to a DNS lookup contains an RRSIG DNS
record in addition to the requested record type. The RRSIG record is a digital signature of the DNS
resource record set answer. The digital signature can be verified by locating the correct public key
found in a DNSKEY record. The DNS record is used in the authentication of DNSKEYs in the lookup
procedure using the chain of trust.
To enable the use of replacement keys, a key rollover procedure is used. New keys are rolled out in
new DNSKEY records in addition to the existing old keys.
For authentication purposes, Alteon uses two different keys in DNSKEY records, with different
DNSKEY records for each. Key Signing Keys (KSKs) are used to sign the Zone Signing Key (ZSKs)
and are exported (publicly) to the parent DNS. ZSKs are used to sign the DNS resource records
(RRs). Because the ZSKs are controlled and used by one specific DNS zone, they can be switched
more easily and more frequently. RFC 4614 recommends changing ZSKs on a monthly basis,
enabling them to be shorter in bit length (for example, 1024). The KSK validity period is usually one
year, and needs a higher bit length (for example, 2048), making it harder to forge. When a new KSK
is created, the delegation signer (DS) record must be transferred to the parent zone, and must be
signed and published there.
When working with GSLB and DNSSEC enabled, the configuration of remote sites must be identical
for all Alteons participating in the GSLB configuration (
/cfg/slb/gslb/site x
).
/cfg/slb/gslb/clntprox
/stats/slb/gslb/clntprox
/cfg/slb/gslb/rule/metric/gmetric/persistence
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...