Chapter 5 Configuring Firewall Load Balancing

Configuring FWLB with VIP and Virtual Interface Redundancy

In Figure 5-2, odd-numbered firewalls are connected to the Layer 2 switches servicing the CSS-OUT-L and CSS-IN-L CSSs. Even-numbered firewalls are connected to the Layer 2 switches servicing the CSS-OUT-R and CSS-IN-R CSSs.

Figure 5-2 FWLB with VIP/Interface Redundancy Configuration

CSS-OUT-L

10.2.1.254

Layer 2 switch

Redundant

interface

CSS-OUT-R

10.2.1.253

Layer 2 switch

10.2.200.1

10.2.200.2

10.2.200.3

10.2.200.11

10.2.200.12

10.2.200.13

Firewall 1

Firewall 2

Firewall 3

10.3.200.1

10.3.200.2

10.3.200.3

10.3.200.11

10.3.200.12

10.3.200.13

10.2.200.4 10.2.200.14

Firewall 4

10.3.200.4

10.3.200.14

Layer 2 switch

10.3.1.224

CSS-IN-L

Redundant VIP

Redundant

interface

Layer 2 switch

10.3.1.223

 

CSS-IN-R

59263

 

Each firewall must have two addresses on either side of it. The first address is used for the next hop on the lower-cost static (primary) path. The second address is used for the next hop on the higher-cost floating-static (secondary) path.

Set the floating-static paths with a higher cost (typically a cost of 10) than those associated with the static paths (typically a cost of 1). If a CSS fails (for example, CSS-OUT-L), CSS-OUT-R will use the higher cost path to send traffic to CSS-IN-L.

 

 

Cisco Content Services Switch Security Configuration Guide

 

 

 

 

 

 

OL-5650-02

 

 

5-11

 

 

 

Page 109
Image 109
Cisco Systems OL-5650-02 manual Fwlb with VIP/Interface Redundancy Configuration