*My comments in blue or marked with '*'.  You do have alot of
questions...I hope I can answer them somewhat clearly.


>Serveriron XL 16 Port. I will be running an active-standby
configuration (if I can understand how that works too! :)).

*The active standby config is very easy, search the CLI docs for
'sym-priority'.  It also works very well.  I strongly suggest that you
do not download the operating code from the site.  Ask Foundry for a
patch release that is right for you.

>
>>
>> The inside source parameter specifies that the mapping applies to the
>> private address sending traffic to the Internet.
>>
>
>OK, I understand that. I have just tried it and it works fine. Any
traffic from the server to the internet will use the IP address that I
have assigned. However, what happens if I want to go from the internet
to the private address, for incoming SSH requests for example?

*It should work both ways.  Just ssh to the outside address. (from the
outside of course).  Make sure that your real servers only possible
route to the outside is through the serveriron.  You cannot use DSR in
this config.


>
>
>
>
>>
>> If you are running dual chassis devices in an active-active or
>> active-standby mode I would wait for the new code to be released
>> shortly.  The new (shortly released) IronWare 9.2 code will greatly
>> simplify this.  Instructions for the new configuration are in the
>> release notes for that release.
>>
>
>OK, Do you know when this will be, would you recommend not using NAT in
an active/standby configuration? What problems occur if you do?

*The new code release is not for the XL series, sorry.  I don't quite
know how to configure this but it involves creating VRRP-E interfaces
for the static nat addresses.  Hopefully the new method in 9.2 will
trickle into the XL code line.


>
>On a side note, in an active/standby configuration. I have been reading
that you should build the configuration on one serveriron and then
replicate it to the second serveriron (and using the backup commands to
configure the backup port) but how does that work if you have virtual
interfaces? I have a number of ve interfaces for each subnet, so do I
just copy the same configuration across? The documentation says that you
need to change the management address? I am unsure what this means!

*Your VEs will need vrrp-e interfaces.  There are lots of bugs in the
config sync stuff...it's pretty brand new.  I usually just tftp the
config off the 'active' SI, edit the ip addresses, vrrp-e priorities and
the sym-priorities and tftp it up to the 'standby'.  One of the cool
things about the 'sym-priority' stuff is that you can have one SI active
for virtual server X and the other active for virtual Y.  So you have
them backing each other up, but you're balancing load across the two
XLs.  


>
>Sorry if I am asking too many questions! Thanks for all your help!
>
>Kind regards
>Tim.
>
>> -----Original Message-----
>> From: [EMAIL PROTECTED]
>> [mailto:[EMAIL PROTECTED]
<mailto:[EMAIL PROTECTED]> ] On Behalf Of Timothy
>> Arnold
>> Sent: Thursday, November 04, 2004 8:20 AM
>> To: [email protected]
>> Subject: [f-nsp] Serveriron / nat
>>
>> Hi Foundry Guru's
>>
>> I am hoping someone could enlighten me on now network address
>> translation works in the serveriron. Here is the situation.
>>
>> I have two vlan's configured - the public vlan with routable IP
>> addresses, this is where the VIP addresses are. The second vlan is a
>> standard 10.x netblock where the servers are located. I have a number
>> of VIPs and load balance a number of web servers - this works great.
>>
>> However, I have a management server that will be accessible via web,
>> ssh etc. Do I need to create a VIP address just for this one server,
>> or can I someway map a public IP address to the internal IP address
>> and vice versa?
>>
>> I hope I have made myself clear!
>>
>> Thanks
>> Tim. :)
>>
>> _______________________________________________
>> foundry-nsp mailing list
>> [email protected]
>> http://puck.nether.net/mailman/listinfo/foundry-nsp
<http://puck.nether.net/mailman/listinfo/foundry-nsp> 
>>
>>
>>
>
>
>
>---
>Timothy Arnold
>Technical Support Engineer
>UK Solutions, Birmingham Road
>Studley, B80 7BG
>
>http://www.uksolutions.co.uk <http://www.uksolutions.co.uk> 
>
>To contact support:
>Via telephone: 08700 681 333
>Via email: [EMAIL PROTECTED]
>
> 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
https://puck.nether.net/pipermail/foundry-nsp/attachments/20041105/e1f088be/attachment.html
From [EMAIL PROTECTED]  Mon Nov  8 14:11:06 2004
From: [EMAIL PROTECTED] (John Willingham)
Date: Mon Nov  8 14:11:12 2004
Subject: [f-nsp] AAA Authentication and FreeRadius
Message-ID: <[EMAIL PROTECTED]>

Guys,

Has anyone had any luck with getting radius authentication setup to
foundry switches/SLBs using FreeRadius (current version 1.0.1) with
sql stored user information? I Have the authentication portion
working, but for somereason I cannot seem to assign privilege levels
to the users logging in.  If anyone has any documents that help point
in the right directions with regards to Attributes or CLI
configuration for the foundry device, that would help head me in the
right direction.

Thanks,
John S. Willingham
From [EMAIL PROTECTED]  Thu Nov 11 13:48:43 2004
From: [EMAIL PROTECTED] (Michael Renner)
Date: Thu Nov 11 13:48:47 2004
Subject: [f-nsp] dns keepalive checks on "unknown" ports
Message-ID: <[EMAIL PROTECTED]>

Hi,

I currently have a "Many-to-one" setup [1] on a Foundry ServerIron XL 
running 07.4.00T12, with 2 virtual servers pointing to 3 real servers, but 
I'm not able to enable keepalive on the "aliased" port as suggested in the 
documentation [2].

[EMAIL PROTECTED](config-rs-www1)#port 153 addr_query "www.domain.com"
Invalid command, zone only applies to DNS port, not 153

Is this intended behaviour for alias ports when not using HTTP (since HTTP 
is IIRC the only protocol which supports Virtualhosts)?

Currently the foundry seems to do dns checks on the "real" and the "aliased" 
port using the configured hostname (i see 2 queries every 3 seconds, opposed 
to 1 query every 3 seconds, when no alias port is used), deactivating both 
ports when the dns server is down.

[1] 
http://www.foundrynet.com/services/documentation/siug/ServerIron_Server_Load_Balancing.html#22178
[2] 
http://www.foundrynet.com/services/documentation/siug/ServerIron_health_checks.html#53798
 


Current setup looks something like that:

---

server port 53
   udp keepalive 3 2

server port 153
   udp keepalive 3 2
   udp keepalive protocol 53

server real www1 1.1.1.1
   port 153
   port 153 keepalive
   port dns
   port dns keepalive
   port dns addr_query "www.domain.com"

[repeat for www2 and www3]

server virtual a.ns.domain.com 1.2.1.1
   port dns
   bind dns www1 dns www2 dns www3 dns

server virtual b.ns.domain.com 1.3.1.1
   port dns
   no port dns translate
   bind dns www1 153 www2 153 www3 153

---



-- 

best regards,
  Michael Renner - Network services

Preisvergleich Internet Services AG
Obere Donaustra?e 63/2, A-1020 Wien
Tel: +43 1 5811609 80
Fax: +43 1 5811609 55
From [EMAIL PROTECTED]  Thu Nov 11 16:55:24 2004
From: [EMAIL PROTECTED] (David J. Hughes)
Date: Thu Nov 11 16:55:50 2004
Subject: [f-nsp] dns keepalive checks on "unknown" ports
In-Reply-To: <[EMAIL PROTECTED]>
References: <[EMAIL PROTECTED]>
Message-ID: <[EMAIL PROTECTED]>


A better idea for aliased ports is to associate them with a
master port.  If you have X aliased ports then you are generating
  X + 1 healthchecks (if you could get them to work in your setup
that is :).  This is not only an excessive load but also provides
a window during which 1 VIP may believe a real server is fine
while another knows it's failed a healthcheck.

If you associate the aliased port with a master port then it
just uses the current state of the master port without re-testing
the service's health.  You can set it up using something like
the following fragment.

---
server port 1110
  connection-log all
  session-sync
  tcp keepalive 5 3
  tcp keepalive use-master-state
---

In this situation, port 1110 is an alias to 110 and is bound using
a "no port 110 translate" on the VIP.  Works like a charm.


David
...


On 12/11/2004, at 4:48 AM, Michael Renner wrote:

> Hi,
>
> I currently have a "Many-to-one" setup [1] on a Foundry ServerIron XL 
> running 07.4.00T12, with 2 virtual servers pointing to 3 real servers, 
> but I'm not able to enable keepalive on the "aliased" port as 
> suggested in the documentation [2].
>
[ ..... ]
>
> ---
>
> server port 53
>   udp keepalive 3 2
>
> server port 153
>   udp keepalive 3 2
>   udp keepalive protocol 53
>
> server real www1 1.1.1.1
>   port 153
>   port 153 keepalive
>   port dns
>   port dns keepalive
>   port dns addr_query "www.domain.com"
>
> [repeat for www2 and www3]
>
> server virtual a.ns.domain.com 1.2.1.1
>   port dns
>   bind dns www1 dns www2 dns www3 dns
>
> server virtual b.ns.domain.com 1.3.1.1
>   port dns
>   no port dns translate
>   bind dns www1 153 www2 153 www3 153
>
> ---

Reply via email to