*My comments in blue or marked with '*'. You do have alot of questions...I hope I can answer them somewhat clearly.
>Serveriron XL 16 Port. I will be running an active-standby configuration (if I can understand how that works too! :)). *The active standby config is very easy, search the CLI docs for 'sym-priority'. It also works very well. I strongly suggest that you do not download the operating code from the site. Ask Foundry for a patch release that is right for you. > >> >> The inside source parameter specifies that the mapping applies to the >> private address sending traffic to the Internet. >> > >OK, I understand that. I have just tried it and it works fine. Any traffic from the server to the internet will use the IP address that I have assigned. However, what happens if I want to go from the internet to the private address, for incoming SSH requests for example? *It should work both ways. Just ssh to the outside address. (from the outside of course). Make sure that your real servers only possible route to the outside is through the serveriron. You cannot use DSR in this config. > > > > >> >> If you are running dual chassis devices in an active-active or >> active-standby mode I would wait for the new code to be released >> shortly. The new (shortly released) IronWare 9.2 code will greatly >> simplify this. Instructions for the new configuration are in the >> release notes for that release. >> > >OK, Do you know when this will be, would you recommend not using NAT in an active/standby configuration? What problems occur if you do? *The new code release is not for the XL series, sorry. I don't quite know how to configure this but it involves creating VRRP-E interfaces for the static nat addresses. Hopefully the new method in 9.2 will trickle into the XL code line. > >On a side note, in an active/standby configuration. I have been reading that you should build the configuration on one serveriron and then replicate it to the second serveriron (and using the backup commands to configure the backup port) but how does that work if you have virtual interfaces? I have a number of ve interfaces for each subnet, so do I just copy the same configuration across? The documentation says that you need to change the management address? I am unsure what this means! *Your VEs will need vrrp-e interfaces. There are lots of bugs in the config sync stuff...it's pretty brand new. I usually just tftp the config off the 'active' SI, edit the ip addresses, vrrp-e priorities and the sym-priorities and tftp it up to the 'standby'. One of the cool things about the 'sym-priority' stuff is that you can have one SI active for virtual server X and the other active for virtual Y. So you have them backing each other up, but you're balancing load across the two XLs. > >Sorry if I am asking too many questions! Thanks for all your help! > >Kind regards >Tim. > >> -----Original Message----- >> From: [EMAIL PROTECTED] >> [mailto:[EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> ] On Behalf Of Timothy >> Arnold >> Sent: Thursday, November 04, 2004 8:20 AM >> To: [email protected] >> Subject: [f-nsp] Serveriron / nat >> >> Hi Foundry Guru's >> >> I am hoping someone could enlighten me on now network address >> translation works in the serveriron. Here is the situation. >> >> I have two vlan's configured - the public vlan with routable IP >> addresses, this is where the VIP addresses are. The second vlan is a >> standard 10.x netblock where the servers are located. I have a number >> of VIPs and load balance a number of web servers - this works great. >> >> However, I have a management server that will be accessible via web, >> ssh etc. Do I need to create a VIP address just for this one server, >> or can I someway map a public IP address to the internal IP address >> and vice versa? >> >> I hope I have made myself clear! >> >> Thanks >> Tim. :) >> >> _______________________________________________ >> foundry-nsp mailing list >> [email protected] >> http://puck.nether.net/mailman/listinfo/foundry-nsp <http://puck.nether.net/mailman/listinfo/foundry-nsp> >> >> >> > > > >--- >Timothy Arnold >Technical Support Engineer >UK Solutions, Birmingham Road >Studley, B80 7BG > >http://www.uksolutions.co.uk <http://www.uksolutions.co.uk> > >To contact support: >Via telephone: 08700 681 333 >Via email: [EMAIL PROTECTED] > > -------------- next part -------------- An HTML attachment was scrubbed... URL: https://puck.nether.net/pipermail/foundry-nsp/attachments/20041105/e1f088be/attachment.html From [EMAIL PROTECTED] Mon Nov 8 14:11:06 2004 From: [EMAIL PROTECTED] (John Willingham) Date: Mon Nov 8 14:11:12 2004 Subject: [f-nsp] AAA Authentication and FreeRadius Message-ID: <[EMAIL PROTECTED]> Guys, Has anyone had any luck with getting radius authentication setup to foundry switches/SLBs using FreeRadius (current version 1.0.1) with sql stored user information? I Have the authentication portion working, but for somereason I cannot seem to assign privilege levels to the users logging in. If anyone has any documents that help point in the right directions with regards to Attributes or CLI configuration for the foundry device, that would help head me in the right direction. Thanks, John S. Willingham From [EMAIL PROTECTED] Thu Nov 11 13:48:43 2004 From: [EMAIL PROTECTED] (Michael Renner) Date: Thu Nov 11 13:48:47 2004 Subject: [f-nsp] dns keepalive checks on "unknown" ports Message-ID: <[EMAIL PROTECTED]> Hi, I currently have a "Many-to-one" setup [1] on a Foundry ServerIron XL running 07.4.00T12, with 2 virtual servers pointing to 3 real servers, but I'm not able to enable keepalive on the "aliased" port as suggested in the documentation [2]. [EMAIL PROTECTED](config-rs-www1)#port 153 addr_query "www.domain.com" Invalid command, zone only applies to DNS port, not 153 Is this intended behaviour for alias ports when not using HTTP (since HTTP is IIRC the only protocol which supports Virtualhosts)? Currently the foundry seems to do dns checks on the "real" and the "aliased" port using the configured hostname (i see 2 queries every 3 seconds, opposed to 1 query every 3 seconds, when no alias port is used), deactivating both ports when the dns server is down. [1] http://www.foundrynet.com/services/documentation/siug/ServerIron_Server_Load_Balancing.html#22178 [2] http://www.foundrynet.com/services/documentation/siug/ServerIron_health_checks.html#53798 Current setup looks something like that: --- server port 53 udp keepalive 3 2 server port 153 udp keepalive 3 2 udp keepalive protocol 53 server real www1 1.1.1.1 port 153 port 153 keepalive port dns port dns keepalive port dns addr_query "www.domain.com" [repeat for www2 and www3] server virtual a.ns.domain.com 1.2.1.1 port dns bind dns www1 dns www2 dns www3 dns server virtual b.ns.domain.com 1.3.1.1 port dns no port dns translate bind dns www1 153 www2 153 www3 153 --- -- best regards, Michael Renner - Network services Preisvergleich Internet Services AG Obere Donaustra?e 63/2, A-1020 Wien Tel: +43 1 5811609 80 Fax: +43 1 5811609 55 From [EMAIL PROTECTED] Thu Nov 11 16:55:24 2004 From: [EMAIL PROTECTED] (David J. Hughes) Date: Thu Nov 11 16:55:50 2004 Subject: [f-nsp] dns keepalive checks on "unknown" ports In-Reply-To: <[EMAIL PROTECTED]> References: <[EMAIL PROTECTED]> Message-ID: <[EMAIL PROTECTED]> A better idea for aliased ports is to associate them with a master port. If you have X aliased ports then you are generating X + 1 healthchecks (if you could get them to work in your setup that is :). This is not only an excessive load but also provides a window during which 1 VIP may believe a real server is fine while another knows it's failed a healthcheck. If you associate the aliased port with a master port then it just uses the current state of the master port without re-testing the service's health. You can set it up using something like the following fragment. --- server port 1110 connection-log all session-sync tcp keepalive 5 3 tcp keepalive use-master-state --- In this situation, port 1110 is an alias to 110 and is bound using a "no port 110 translate" on the VIP. Works like a charm. David ... On 12/11/2004, at 4:48 AM, Michael Renner wrote: > Hi, > > I currently have a "Many-to-one" setup [1] on a Foundry ServerIron XL > running 07.4.00T12, with 2 virtual servers pointing to 3 real servers, > but I'm not able to enable keepalive on the "aliased" port as > suggested in the documentation [2]. > [ ..... ] > > --- > > server port 53 > udp keepalive 3 2 > > server port 153 > udp keepalive 3 2 > udp keepalive protocol 53 > > server real www1 1.1.1.1 > port 153 > port 153 keepalive > port dns > port dns keepalive > port dns addr_query "www.domain.com" > > [repeat for www2 and www3] > > server virtual a.ns.domain.com 1.2.1.1 > port dns > bind dns www1 dns www2 dns www3 dns > > server virtual b.ns.domain.com 1.3.1.1 > port dns > no port dns translate > bind dns www1 153 www2 153 www3 153 > > ---
