Fortinet FortiADC D-Series Handbook

Add to My manuals
470 Pages

advertisement

Fortinet FortiADC D-Series Handbook | Manualzz

Chapter 5: Link Load Balancing Configuring proximity route settings

Type

Timeout

Source IPv4

Netmask Bits

Destination IPv4

Netmask Bits

Guidelines

The default is 300 seconds.

Number of bits in a subnet mask to specify a network segment that should following the persistence rule.

Number of bits in a subnet mask to specify a network segment that should following the persistence rule.

For example, if you set this to 24, and the system chooses a particular gateway router for destination IP 192.168.1.100, the system will select that same gateway for traffic to all destination IPs in subnet 192.168.1.0/24.

Source Address

Timeout

Source IPv4

Netmask Bits

The default is 300 seconds.

Number of bits in a subnet mask to specify a network segment that should following the persistence rule. The default is 32, but you can set it to any value between 1 and 32.

For example, if you set this to 24, and the system chooses a particular gateway router for client IP 192.168.1.100, the system will select that same gateway for subsequent client requests when the subsequent client belongs to subnet 192.168.1.0/24.

Destination Address

Timeout

Destination IPv4

Netmask Bits

The default is 300 seconds.

Number of bits in a subnet mask to specify a network segment that should following the persistence rule.

Configuring proximity route settings

The proximity route feature enables you to associate link groups with efficient routes. Proximity routes can improve user experience over the WAN because traffic is routed over fast routes.

You can use either or both of these methods: l l

Static Table—You specify the gateways to use for traffic on destination networks.

Dynamic Detection—The system polls the network for efficient routes. The algorithm selects a gateway based on latency.

If you configure both, the system checks the static table first for a matching route and, if any, uses it. If there is no matching static route, the system uses dynamic detection.

Before you begin:

156 FortiADC D-Series Handbook

Fortinet Technologies, Inc.

Configuring proximity route settings Chapter 5: Link Load Balancing l l

You must have knowledge of IP addresses used in outbound network routes to configure a static route.

You must have Read-Write permission for Link Load Balance settings.

To configure a proximity route:

1. Go to Link Load Balance > Link Group.

2. Click the Proximity Route tab.

3. Complete the configuration as described in

Table 32

.

4. Save the configuration.

 Table 32: Proximity route rule configuration

Type Guidelines

Mode l

Static Table First—Consult the static table first. If no match, use dynamic detection.

l

Static Table Only—Use the static table; do not use dynamic detection.

l

Dynamic Detect Only—Use dynamic detection; do not use the static table.

l

Disable—Do not use the proximity route configuration.

Static Table

Type

ISP Name

IP Subnet l

ISP—Use an ISP address object.

l

Subnet—Specify an IP netmask manually.

Routes that are specified manually have priority over ISP address object entries.

If you use the ISP configuration type, select an ISP address book configuration object.

If an address exists in multiple ISP address books, the route entries have priority as follows:

1. User-defined entries.

2. Entries from an address book that has been imported.

3. Entries from the predefined address book (default for the firmware image).

If you use the Subnet configuration type, specify a destination IP address and netmask.

Gateway Select a gateway configuration object. The gateway must be able to route packets to the destination IP address that you have specified.

Dynamic Detect

Protocol l

ICMP—Use ICMP to detect routes. Calculate proximity by the smaller RTT.

l

ICMP and TCP—Some hosts do not respond to ICMP requests. Specify this option to use both ICMP and TCP to detect routes and RTT. For TCP detection, port 7

(TCP echo) is used. A connection refused or connection reset by the destination is treated as successful detection.

FortiADC D-Series Handbook

Fortinet Technologies, Inc.

157

advertisement

advertisement

Table of contents