David J. Hughes wrote:
> 
> A better idea for aliased ports is to associate them with a
> master port.  If you have X aliased ports then you are generating
>  X + 1 healthchecks (if you could get them to work in your setup
> that is :).  This is not only an excessive load but also provides
> a window during which 1 VIP may believe a real server is fine
> while another knows it's failed a healthcheck.

Ahhh, yeah, that would be great if it wasn't for strange limitations in 
the foundry firmware. Quoting from the documentation [1]:

"You cannot base an alias port?s health on the health of a UDP port or a 
port that is not well-known to the ServerIron."

Bummer. But since it's only DNS the "excessive" requests aren't really a 
problem. About the window - oh well - something I've to live with I 
guess ;).

Other than that my setup looks fine or is there still room for improvement?

[1] 
http://www.foundrynet.com/services/documentation/siug/ServerIron_health_checks.html#55152

best regards,
Michael
From [EMAIL PROTECTED]  Thu Nov 11 20:01:01 2004
From: [EMAIL PROTECTED] (David J. Hughes)
Date: Thu Nov 11 20:01:15 2004
Subject: [f-nsp] dns keepalive checks on "unknown" ports
In-Reply-To: <[EMAIL PROTECTED]>
References: <[EMAIL PROTECTED]>
        <[EMAIL PROTECTED]>
        <[EMAIL PROTECTED]>
Message-ID: <[EMAIL PROTECTED]>


On 12/11/2004, at 10:37 AM, Michael Renner wrote:

> Ahhh, yeah, that would be great if it wasn't for strange limitations 
> in the foundry firmware. Quoting from the documentation [1]:
>
> "You cannot base an alias port?s health on the health of a UDP port or 
> a port that is not well-known to the ServerIron."

Wow!  I've seen some "odd" things on the SI's but that one just about 
takes the cake.  Logic, useability, and firmware development strategies 
are obviously mutually exclusive :)



> Bummer. But since it's only DNS the "excessive" requests aren't really 
> a problem. About the window - oh well - something I've to live with I 
> guess ;).

We had about 20 port aliased VIPs (to handle legacy addresses and other 
ugliness) and the "window" actually was a significant problem.  Luckily 
for us these were POP3 VIPs so I didn't find this issue about non-well 
known tcp ports.

>
> Other than that my setup looks fine or is there still room for 
> improvement?

Looks fine to me.


David
...

Reply via email to