
Chapter 5 Configuring Firewall Load Balancing
Configuring FWLB
Firewall Synchronization
Firewall solutions providing Stateful Inspection, such as Check Point™
Firewall synchronization (as shown in Figure
Note For details on configuring firewall synchronization, refer to your specific firewall
documentation. In the case of a
Configuring FWLB
A CSS must exist on each side of the firewall to control which firewall is selected for each flow. Within the firewall configuration, you must configure both the local and remote CSSs with the same firewall index number.
To avoid dropping packets, the CSS directs all packets between a pair of IP addresses across the same firewall. This applies to packets flowing in either direction. If a failure occurs on one path, all traffic will use the remaining path or balance traffic on the remaining paths.
Note You must define the firewall index before you define the firewall route or the CSS will return an error message. To configure the route, see the ip route... firewall command.
|
| Cisco Content Services Switch Security Configuration Guide |
|
|
|
|
| ||
|
|
|
| |
|
|
|