cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
599
Views
0
Helpful
6
Replies

ACE: load balancing servers using DMZ ports on FWSM

cfajardo1_2
Level 1
Level 1

devices; (2 core with the ff config)

6500

fwsm

idsm

msfc

SETUP;

Servers are connected to the dmzs on the core

REQUIREMENT;

to load balance the servers

QUESTION;

Using the ACE module, is it possibe to load balance the servers which are connected to the port which is configured as DMZ?

Thanks

6 Replies 6

cfajardo1_2
Level 1
Level 1

note that the 2 fwsm are on active/standby mode.

thanks

cfajardo1_2
Level 1
Level 1

on cisco doc OL-9375-01 chapter 16, it discussess about firewall load balancing but never has been a server farm conneted on a firwall port (dmz on this case)

Gilles Dufour
Cisco Employee
Cisco Employee

does not matter where the servers are connected.

However, be aware that the flows from client to server needs to go through the loadbalancer BUT also the flows server to client.

So, you should be careful where you attach the ACE module.

The easier would be to attach to the DMZ as well between the FW and the servers.

Gilles.

Hello Giles,

"The easier would be to attach to the DMZ as well between the FW and the servers".

The above statement is not clear to me. Please elaborate.

thanks.

--outside_vlan -- FW -- DMZ_vlan -- ACE --- Servers

G.

Hi Giles,

- so the ACE will be in between the DMZ and the servers?

- does your outside vlan mean users vlan?

Thanks