Web example: Configuring ISP-based outbound link load balancing

Network configuration

As shown in Figure 1, an enterprise accesses the external servers through ISP links Link_a, Link_b, and Link_c provided by ISP_A, ISP_B, and ISP_C, respectively. Configure outbound link load balancing to meet the following requirements:

Figure 1 Network diagram

 

Device

Interface

IP address

Device

Interface

IP address

Device

GE1/0/1

30.1.1.1/24

Router A

GE1/0/1

30.1.1.2/24

Device

GE1/0/2

20.1.1.1/24

Router B

GE1/0/1

20.1.1.2/24

Device

GE1/0/3

10.1.1.124

Router C

GE1/0/1

10.1.1.2/24

Device

GE1/0/4

192.168.100.82/24

 

 

 

 

Software versions used

This configuration example was created and verified on E9671 of the M9000-X06 device.

Procedures

  1. Assign IP addresses to interfaces and add the interfaces to security zones.

# On the top navigation bar, click the Network tab.

# From the navigation pane, select Interface Configuration > Interfaces.

# Click the Edit icon for GE 1/0/1.

# In the dialog box that opens, configure the interface:

# Add GE 1/0/2 to the Untrust security zone and set its IP address to 20.1.1.1./24 in the same way you configure GE 1/0/1.

# Add GE 1/0/3 to the Untrust security zone and set its IP address to 10.1.1.1/24 in the same way you configure GE 1/0/1.

# Add GE 1/0/4 to the Trust security zone and set its IP address to 192.168.100.82/24 in the same way you configure GE 1/0/1.

  1. Configure routes:

This section uses static routes as an example. You can also configure a dynamic routing protocol as needed.

# On the top navigation bar, click Network.

# From the navigation pane, select Routing > Static Routing.

# On the IPv4 Static Routing tab, click Create.

# In the dialog box that opens, configure an IPv4 static route with next hop IP address 30.1.1.2:

# On the IPv4 Static Routing tab, click Create.

# In the dialog box that opens, configure an IPv4 static route with next hop IP address 20.1.1.2:

# On the IPv4 Static Routing tab, click Create.

# In the dialog box that opens, configure an IPv4 static route with next hop IP address 10.1.1.2:

  1. Configure security policies.

# On the top navigation bar, click Policies.

# From the navigation pane, select Security Policies > Security Policies.

# Click Create.

# In the dialog box that opens, configure a security policy named Trust-to-Untrust:

# Configure a security policy named Local-to-Untrust:

  1. Configure ICMP probe templates.

# On the top navigation bar, click Objects.

# From the navigation pane, click Health Monitoring.

# Click Create.

# In the dialog box that opens, configure an ICMP probe template named ta, as shown in Figure 2.

Figure 2 Creating probe template ta

 

# Click OK.

# Configure an ICMP probe template named tb, as shown in Figure 3.

Figure 3 Creating probe template tb

 

# Click OK.

# Configure an ICMP probe template named tc, as shown in Figure 4.

Figure 4 Creating probe template tc

 

# Click OK.

  1. Configure outbound dynamic NAT rules.

# On the top navigation bar, click Policies.

# From the navigation pane, select Interface NAT > IPv4 > Dynamic NAT.

# On the Outbound Dynamic NAT (Object Group-Based) tab, click Create.

# Create an outbound dynamic NAT rule named nat_ra, as shown in Figure 5:

Click OK.

Figure 5  Configuring an outbound dynamic NAT rule named nat_ra

 

# Create an outbound dynamic NAT rule named nat_rb, as shown in Figure 6:

Figure 6 Configuring an outbound dynamic NAT rule named nat_rb

 

# Create an outbound dynamic NAT rule named nat_rc, as shown in Figure 7:

Figure 7 Configuring an outbound dynamic NAT rule named nat_rc

 

  1. Configure links.

# On the top navigation bar, click Polices.

# From the navigation pane, select Load Balancing > Links.

# Click Create.

# In the dialog box that opens, configure a link named link-a as shown in Figure 8.

# Click OK.

Figure 8 Creating link link-a

 

# Click Create.

# In the dialog box that opens, configure a link named link-b as shown in Figure 9.

# Click OK.

Figure 9 Creating link link-b

 

# Click Create.

# In the dialog box that opens, configure a link named link-c as shown in Figure 10.

# Click OK.

Figure 10 Creating link link-c

 

  1. Configure link groups.

# On the top navigation bar, click Polices.

# From the navigation pane, select Link Load Balancing > Outbound Link LB.

# On the Link Group tab, click Create.

# In the dialog box that opens, configure a link group named link-group-a as shown in Figure 11.

# Click OK.

Figure 11 Creating link group link-group-a

 

# On the Link Group tab, click Create.

# In the dialog box that opens, configure a link group named link-group-b as shown in Figure 12.

# Click OK.

Figure 12 Creating link group link-group-b

 

# On the Link Group tab, click Create.

# In the dialog box that opens, configure a link group named link-group-c as shown in Figure 13

# Click OK.

Figure 13 Creating link group link-group-c

 

  1. Import ISP information.

# On the top navigation bar, click Polices.

# From the navigation pane, select Load Balancing > ISP.

# Select file lbispinfo.tp.

# Click Import.

Figure 14 Importing ISP information

 

  1. Configure classes.

# On the top navigation bar, click Polices.

# From the navigation pane, select Link Load Balancing > Outbound Link LB.

# On the Class tab, click Create.

# In the dialog box that opens, configure a class named class-isp-a as shown in Figure 15.

# Click OK.

Figure 15 Creating class class-isp-a

 

# On the Class tab, click Create.

# In the dialog box that opens, configure a class named class-isp-b as shown in Figure 16.

# Click OK.

Figure 16 Creating class class-isp-b

 

# On the Class tab, click Create.

# In the dialog box that opens, configure a class named class-isp-c as shown in Figure 17.

# Click OK.

Figure 17 Creating class class-isp-c

 

# On the Class tab, click Create.

# In the dialog box that opens, configure a class named class-finance as shown in Figure 18.

# Click OK.

Figure 18 Creating class class-finance

 

  1. Configure IPv4 routing policies.

# On the top navigation bar, click Polices.

# From the navigation pane, select Link Load Balancing > Outbound Link LB.

# In the Global configuration area on the IPv4 Routing Policy tab, select LB service and Link protection.

Figure 19 Global configuration

 

# In the Policy area on the IPv4 Routing Policy tab, click Create.

# In the dialog box that opens, configure an IPv4 routing policy for class class-finance:

Figure 20 Creating a policy for class class-finance

 

# In the Policy area on the IPv4 Routing Policy tab, click Create.

# In the dialog box that opens, configure an IPv4 routing policy for class class-isp-a:

Figure 21 Creating a policy for class class-isp-a

 

# In the Policy area on the IPv4 Routing Policy tab, click Create.

# In the dialog box that opens, configure an IPv4 routing policy for class class-isp-b:

Figure 22 Creating a policy for class class-isp-b

 

# In the Policy area on the IPv4 Routing Policy tab, click Create.

# In the dialog box that opens, configure an IPv4 routing policy for class class-isp-c:

Figure 23 Creating a policy for class class-isp-c

 

# View the configured IPv4 routing policies as shown in Figure 24.

Figure 24 IPv4 routing policies

 

Verifying the configuration

# On the top navigation bar, click the Monitor tab.

# From the navigation pane, select Statistics > Outbound Link LB Statistics > Links.

# View the statistics of link link-a as shown in Figure 25. Traffic from subnet 192.168.200.0/24 in the finance department matches class class-finance, and is distributed to link group link-group-a.

Figure 25 Statistics of traffic from the finance department

 

# View the statistics of link link-a as shown in Figure 26. Traffic destined for ISP-A matches class class-isp-a, and is distributed to link group link-group-a.

Figure 26 Statistics of traffic destined for ISP_A

 

# View the statistics of link link-b as shown in Figure 27. Traffic destined for ISP-B belongs to class class-isp-b, and is distributed to link group link-group-b.

Figure 27 Statistics of traffic destined for ISP_B

 

# View the statistics of link link-c as shown in Figure 28. Traffic destined for ISP_C belongs to class class-isp-c, and is distributed to link group link-group-c.

Figure 28 Statistics of traffic destined for ISP_C