[精选]F5负载均衡设备组网架构概述.pptx
《[精选]F5负载均衡设备组网架构概述.pptx》由会员分享,可在线阅读,更多相关《[精选]F5负载均衡设备组网架构概述.pptx(36页珍藏版)》请在淘文阁 - 分享文档赚钱的网站上搜索。
1、F5 LTM组网架构组网架构F5 售前工程师单臂接入模式单臂接入模式双臂接入模式双臂接入模式远程节点模式远程节点模式参加独立参加独立SSL/WA/ASMSSL/WA/ASM设备设备防火墙负载均衡防火墙负载均衡多链路接入多链路接入灾备站点静态路由注入灾备站点静态路由注入AgendaAgendaLTM单臂接入模式臂接入模式3单臂接入模式下的网臂接入模式下的网络物理物理结构构4核心三层交换效劳器效劳器LTMLTM外部网络Vlan 1串口心跳线LTM单臂源地址替臂源地址替换接入典型架构接入典型架构设计5Core SwitchCore SwitchServerServer网络同步-独立Vlan串口心跳N
2、etworkIP:192.168.0.1GW:192.168.0.254IP:192.168.0.2GW:192.168.0.254SelfIP:192.168.0.200GW:192.168.0.254VS:192.168.0.100SNAT AutomapSelfIP:192.168.0.201GW:192.168.0.254VS:192.168.0.100SNAT AutomapHSRP 192.168.0.254TrunkTrunkTrunkActiveBackup单臂接入臂接入-源地址替源地址替换模式数据模式数据访问流程流程6核心三层交换效劳器效劳器LTMClient192.168.
3、0.1192.168.1.10GW:192.168.1.254192.168.1.11GW:192.168.1.254VS:192.168.1.1:80SelfIP:192.168.1.253GW:192.168.1.254192.168.1.254192.168.0.254SIPSportDIPDport192.168.0.16787192.168.1.180192.168.1.2538888192.168.1.1180192.168.1.1180192.168.1.2538888192.168.1.180192.168.0.16787源地址替源地址替换后的后的处理理7核心三层交换效劳器效劳
4、器LTMClient192.168.0.1192.168.1.10GW:192.168.1.254192.168.1.11GW:192.168.1.254VS:192.168.1.1:80SelfIP:192.168.1.253GW:192.168.1.254192.168.1.254192.168.0.254 Profilewhen _REQUEST :header insert Client_IP=IP:client_addriRules只有 协议的时候,可以通过将源地址插入到客户端请求的 Header里,然后在效劳器上通过读取这个Header,获得客户端的真实源IP地址单臂接入臂接入-n
5、path模式数据模式数据访问流程流程8核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.1.10Lo:192.168.1.1GW:192.168.1.254192.168.1.11Lo:192.168.1.1GW:192.168.1.254VS:192.168.1.1:80SelfIP:192.168.1.253GW:192.168.1.254192.168.1.254192.168.0.254SIPSportDIPDport 192.168.0.1 6787 192.168.1.180192.168.0.1 6787 192.168.1.180 192.168.
6、1.180192.168.0.1 6787单臂接入臂接入-效效劳器非直器非直连模式无源地址替模式无源地址替换9核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.2.10GW:192.168.2.254192.168.2.11GW:192.168.2.254VS:192.168.1.1:80SelfIP:192.168.1.253GW:192.168.1.254192.168.2.254192.168.0.254SIPSportDIPDport192.168.0.16787192.168.1.180192.168.0.16787192.168.2.1180192.1
7、68.2.1180192.168.0.16787192.168.1.180192.168.0.16787无源地址替换的单臂接入模式使用比较少,通常用于对现网不能改造的情况这种模式下需要在核心三层交换上启用源地址路由,将效劳器的所有返回数据包转向LTM,这样才能保证进出的连接完整性建议在这种结构下采用源地址替换以减小网络复杂程度192.168.1.254192.168.1.254同网段同网段访问处理理-必必须通通过SNAT实现10核心三层交换客户端效劳器LTM192.168.1.10GW:192.168.1.254192.168.1.11GW:192.168.1.254VS:192.168.1.
8、1:80IP:192.168.1.253GW:192.168.1.254192.168.1.254SIPSportDIPDport192.168.0.106787192.168.1.180192.168.1.2538888192.168.1.1180192.168.1.1180192.168.1.2538888192.168.1.180192.168.0.16787单臂接入臂接入-效效劳器更改网关数据器更改网关数据访问流程流程11核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.1.10GW:192.168.1.253192.168.1.11GW:192.168.
9、1.253VS:192.168.1.1:80SelfIP:192.168.1.253GW:192.168.1.254192.168.1.254192.168.0.254SIPSportDIPDport192.168.0.16787192.168.1.180192.168.0.16787192.168.1.1180192.168.1.1180192.168.0.16787192.168.1.180192.168.0.16787效效劳器更改网关后的直接器更改网关后的直接访问效效劳器器问题12核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.1.10GW:192.168
10、.1.253192.168.1.11GW:192.168.1.253VS:192.168.1.1:80IP:192.168.1.253GW:192.168.1.254192.168.1.254192.168.0.254SYNSYNSYN-ACKSIPSportDIPDport192.168.0.16787192.168.1.1180192.168.1.1180192.168.0.16787FastL4 Profile双臂接入模式双臂接入模式13LTM双臂接入模式典型架构双臂接入模式典型架构设计14VLAN EXTServerServer网络同步-独立Vlan串口心跳NetworkIP:192.
11、168.0.3GW:192.168.0.254IP:192.168.0.4GW:192.168.0.254SelfIP EXT:192.168.1.200SelfIP INT:192.168.0.200GW:192.168.1.254VS:192.168.1.100HSRP 192.168.0.254ActiveBackupVLAN INTVLAN EXTVLAN INTSelfIP EXT:192.168.1.200SelfIP INT:192.168.0.200GW:192.168.1.254VS:192.168.1.100 FIP:192.168.0.254LB ServerIP:192
12、.168.0.1GW:192.168.0.250LB ServerIP:192.168.0.2GW:192.168.0.250 FIP:192.168.0.254HSRP 192.168.1.254双臂接入双臂接入-效效劳器直器直连15核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.2.10GW:192.168.2.254192.168.2.11GW:192.168.2.254VS:192.168.1.1EXTIP:192.168.1.253/VLAN EXTINTIP:192.168.2.254/VLAN INTGW:192.168.1.254192.168.
13、1.254192.168.0.254SIPSportDIPDport192.168.0.16787192.168.1.180192.168.0.16787192.168.2.1180192.168.2.1180192.168.0.16787192.168.1.180192.168.0.16787双臂接入双臂接入-串串联部署部署-扩展端口展端口16核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.2.10GW:192.168.2.254192.168.2.11GW:192.168.2.254VS:192.168.1.1EXTIP:192.168.1.253/VLAN
14、 EXTINTIP:192.168.2.254/VLAN INTGW:192.168.1.254192.168.1.254192.168.0.254效劳器接入交换SIPSportDIPDport192.168.0.16787192.168.1.180192.168.0.16787192.168.2.1180192.168.2.1180192.168.0.16787192.168.1.180192.168.0.16787双臂接入双臂接入-旁挂模式旁挂模式17核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.2.10GW:192.168.2.254192.168.2.
15、11GW:192.168.2.254VS:192.168.1.1:80EXTIP:192.168.1.253/VLAN EXTINTIP:192.168.2.254/VLAN INTGW:192.168.1.254192.168.1.254192.168.0.254SIPSportDIPDport192.168.0.16787192.168.1.180192.168.0.16787192.168.2.1180192.168.2.1180192.168.0.16787192.168.1.180192.168.0.16787External_vlanInternal_vlan旁挂模式下LTM可以用
16、不同的端口接入核心交换,也可以采用端口捆绑模式接入核心交换,然后在端口捆绑里通过VLAN tag方式来划分多个VLAN旁挂模式下的效旁挂模式下的效劳器直接器直接访问18核心三层交换效劳器效劳器LTMClient192.168.0.1192.168.2.10GW:192.168.2.254192.168.2.11GW:192.168.2.254VS:192.168.1.1EXTIP:192.168.1.253/VLAN EXTINTIP:192.168.2.254/VLAN INTGW:192.168.1.254192.168.1.254192.168.0.254SIPSportDIPDport
17、192.168.0.16787192.168.2.1180192.168.0.16787192.168.2.1180192.168.2.1180192.168.0.16787FastL4 Profile双臂接入双臂接入-防止防止Spanning TreeF5 LTM有非常快速的切换机制200ms,切换完成后会发送ARP播送Spanning Tree的重算机制在一些情况下会阻止对端设备收到ARP播送不同设备的ARP更新机制有时会带来很大的麻烦通常情况下,也不建议采用效劳器双网卡接入19核心三层交换效劳器效劳器LTMClient效劳器接入交换核心三层交换LTM效劳器接入交换Client远程程节点模
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 精选 F5 负载 均衡 设备 组网 架构 概述
限制150内