
Spoof
When the Spoof option is enabled on a cluster, Equalizer uses the client’s
IP address as the source IP address in all packets sent to a server in that
cluster.
When Spoof is enabled, all server responses to client requests that came
through the Equalizer cluster IP address must be routed by the server
back to the client through Equalizer. In many cases, the easiest way to do
this is to set the default gateway on the server instances in the server pool
on a cluster to Equalizer’s IP address on the server VLAN. If this is not
possible, you can establish static routes on the server to send responses
to specific client IP addresses to Equalizer’s IP address on the VLAN.
If you disable Spoof, the server receiving the request will see Equalizer’s
IP address as the client address because the TCP connection to the client is
terminated when the request is routed. The server will therefore send its
response back to Equalizer’s IP address.
When the Spoof flag is disabled on a Layer 4 cluster:
If there is more than one VLAN defined, all server instances on a server
pool must be located on the second defined VLAN in the configuration (the
VLAN that appears after the Default VLAN in the GUI, in ifconfig output,
and in the configuration file), so that source NAT will work correctly. This
is because the source IP address used when spoof is disabled is the
Equalizer IP address on that VLAN.
Click on the Commit button after making changes.
TCP Cluster Persistence
The TCP Cluster Configuration Persistence screen is used to configure Sticky Netmask values, Timeouts and
assign the Inter Cluster sticky flag to the selected TCP cluster. It can be accessed by selecting a cluster from the
left navigational pane and selecting the Configuration > Persistence tabs.
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
275
Equalizer Administration Guide
Comentários a estes Manuais