Chapter 14 Load Balancing in the P333R-LB

Demilitarized Zone (DMZ) Configuration Example

The following figure illustrates Transparent FWLB with DMZ configuration.

Figure 14.2 Transparent Routing FWLB Sample DMZ Configuration

Firewall 1

 

 

10.1.1.1

 

 

 

10.4.1.3

10.1.1.3

10.3.1.1

10.2.1.1

193.170.1.1

193.170.1.2

 

 

 

10.2.1.3

LAN

 

Internet

10.1.1.2

 

P333R-LB 1

P333R-LB 2

Access Router

10.3.1.2

10.2.1.2

 

Firewall 2

 

RSG

10.3.1.3fw- group

P333R-LB 3

193.170.2.3

DMZ

Note:

1.When configuring routing firewalls as Real Servers, you must give an ID to each Real Server. This ID must match the ID given to the same firewall on the second load balancer.

2.The P333R-LB performs load balancing on traffic that arrives to its routing interfaces. Therefore, IP routes in the network must be configured to pass through the P333R-LB.

To configure your network as in Figure 14.2, the following should be done:

The LAN routers (or hosts) should be configured with 10.4.1.3 as the next hop toward the WAN (the default gateway in many cases).

The access router should be configured with 193.170.1.1 as the next hop toward the LAN.

The firewalls should be configured with 10.1.1.3 as the next hop towards the LAN, and 10.2.1.3 as the next hop toward the WAN (internet).

The firewalls must be configured to allow ICMP Ping to pass between the two load balancers (10.1.1.3 and 10.2.1.3) for health-check purposes.

Each load balancer must be configured to two virtual firewall services. In Figure 14.2, P333R-LB1 should be assigned to the WAN and DMZ, P333R-LB2 to the LAN and DMZ, and P333R-LB3 to the LAN and WAN.

Avaya P333R-LB User’s Guide

9

Page 151
Image 151
Avaya P333R-LB manual Demilitarized Zone DMZ Configuration Example, Firewall

P333R-LB specifications

The Avaya P333R-LB is a robust and versatile switch that is part of Avaya's portfolio aimed at enterprise networking solutions. This switch is designed to enhance the performance and scalability of network infrastructure while ensuring high availability and reliability.

One of the main features of the P333R-LB is its Layer 3 switching capability, which allows for efficient routing within an organization's network. This capability is particularly beneficial for organizations with multiple VLANs, as it simplifies the routing process and ensures that data packets are transmitted in the most efficient manner possible.

The P333R-LB is equipped with advanced Quality of Service (QoS) features to prioritize traffic based on the type of application being used. This ensures that critical applications, such as VoIP and video conferencing, receive the necessary bandwidth and low latency required for optimal performance. Additionally, it supports both IPv4 and IPv6 protocols, making it adaptable to a variety of networking environments.

Another important feature of the Avaya P333R-LB is its stackable design. This allows multiple switches to be interconnected, creating a single logical unit. This stacking capability not only simplifies management but also increases overall network capacity and redundancy. In case of a hardware failure, the stack can continue operating without interruption, maintaining network integrity and service continuity.

The switch also integrates advanced security features, including support for MAC filtering, access control lists, and port security. These features help to safeguard network resources from unauthorized access and potential threats. Moreover, the P333R-LB supports 802.1X port-based authentication, which adds an additional layer of security during user access to the network.

The Avaya P333R-LB comes with multiple Gigabit Ethernet ports, allowing for high-speed connectivity to devices such as servers, workstations, and IP phones. This ensures that all devices on the network can communicate effectively, supporting the demands of modern enterprise environments.

For management and monitoring, the P333R-LB offers a user-friendly web interface along with SNMP support, enabling network administrators to easily configure settings and monitor network performance. This simplicity in management is crucial for IT teams that need to ensure optimal network performance while minimizing downtime.

In summary, the Avaya P333R-LB is a feature-rich, scalable, and reliable switch that meets the needs of demanding enterprise networks. With its advanced technologies, QoS support, stackable design, robust security features, and high-speed connectivity options, the P333R-LB is positioned to support a wide range of applications and enhance overall network performance.