Loadbalancer.Org Appliance Setup V5.9
Total Page:16
File Type:pdf, Size:1020Kb
Loadbalancer.org Appliance Setup v5.9 This document covers the basic steps required to setup the Loadbalancer.org appliances. Please pay careful attention to the section on the ARP problem for your real server OS. Copyright © Loadbalancer.org Limited 2002-2007 Table of Contents Loadbalancer.org Appliance Setup v5.8..............................................................................................1 Planing.............................................................................................................................................3 Example Layer 4 configuration.......................................................................................................4 Refining the planing....................................................................................................................5 Finalizing the network diagram.......................................................................................................6 Example Network Diagram: Direct Routing Mode.........................................................................7 Example Network Diagram: Network Address Translation Mode.................................................8 A bit more detail on the NAT style set up.......................................................................................9 A Firewall is simple in theory but can be complex in practice:....................................................11 Explaining the RIP & VIP.............................................................................................................12 Configuring your Loadbalancer.org appliance..............................................................................13 Physical network configuration................................................................................................13 Modify Logical Virtual Server Configuration..........................................................................15 Modify Logical Real Server Configuration..............................................................................16 Solving the ARP problem (Direct Routing method only).............................................................17 The procedure for Windows 2000/2003 web servers is as follows :.......................................18 The procedure for Linux ..........................................................................................................21 Transparent Proxy (Horms method)....................................................................................21 Or change the arp behavior with arp_ignore/arp_anounce.................................................22 The procedure for Solaris..........................................................................................................23 The procedure for Mac OS X & BSD.......................................................................................23 Testing...........................................................................................................................................24 Example Layer 7 configuration.....................................................................................................25 Example Network Diagram: Layer 7 Proxy mode........................................................................25 Configuring your Loadbalancer.org appliance..............................................................................26 Modify logical Virtual Servers (Layer 7 HAProxy).................................................................27 Modify Logical Real Server Configuration (Layer 7 HAProxy)..............................................28 Modify logical Virtual Servers (SSL Termination Pound).......................................................29 Manage this SSL certificate......................................................................................................30 How do I import certificates exported from Windows Server?.....................................................31 Windows........................................................................................................................................31 UNIX.............................................................................................................................................31 Planing Setting up a load balancer from Loadbalancer.org is easy, but a little planing never hurt anyone. Deciding on your objectives is always the first step, are you looking for increased performance, reliability, ease of maintenance or all three? A load balancer can increase performance Performance by allowing you to utilize several cheap servers to do the work of one web site. Running a web site on one server gives you a single point of failure, utilizing a load Reliability balancer moves the point of failure to the load balancer. At Loadbalancer.org we advise that you only deploy load balancers as clustered pairs for this very reason. Using the load balancer you can easily Maintenance bring servers on and off line to perform maintenance on individual web servers. Loadbalancer.org appliances are primarily for fast layer 4 load balancing of local server clusters. Like many other commercial products the Linux Virtual Server (LVS) is the open source core of the routing engine. The appliances also support SSL termination (Pound) and Layer 7 (HA-Proxy) load balancing for environments in the unfortunate position of requiring cookie persistence or URL switching. From the configuration perspective the 3 methods are completely separate this is a functional design decision based on the fact that LVS is a router and Pound/Ha-Proxy are application proxies. Layer 4 Direct Routing Ultra-fast local server based load balancing. (recommended) Requires handling the ARP issue on the real servers. Layer 4 NAT(masq) Fast layer 4 load balancing, the appliance becomes the default gateway for the real servers. Layer 4 TUN Similar to DR but works across IP encapsulated tunnels. Layer 7 - SSL Pound Usually required in order to process cookie persistence on the load balancer. Processor intensive. Layer 7 HA-Proxy Layer 7 allows great flexibility including full SNAT and WAN load balancing + Cookie insertion and URL switching. Much slower than Layer 4. Example Layer 4 configuration For this example we will assume that we would like to balance the load over three Windows 2000 web servers, all three web servers are running the same web site which uses both HTTP & HTTPS. All of the web servers will talk to a shared Oracle database to handle persistence. The session table is held on the database so it doesn't matter which web server answers the client request. HTTPS is often said to require a persistent connection to the client, it doesn't, but it does help performance not to have to re-negotiate the key for every connection. When a client requests HTTPS we will configure the load balancer to keep the connection persistent (Always use the same server) for 5mins. www.example.com currently points at a single web server with its own valid fixed IP address, the firewall then NATs this valid IP address to the web servers RIP address 192.168.1.10. In order to provide a smooth transition, the plan is to set up the clustered load balancer on the same subnet as two new servers. Test it carefully to make sure it detects when the servers are up or down and balances the load evenly. Then when confident everything is OK change the firewall so that it NATs the external IP of www.example.com to the external floating VIP of the load balancer. After an extended live testing period, the original web server can be added to the cluster. This method ensures that if at any stage you run into trouble you can quickly change the firewall back to the original configuration. Refining the planing Now step back and review the plan. Load balancers only work effectively if the web servers are completely stateless, do your web servers store persistent information on local drives? Images (jpeg,png,gif etc.) Files (html,php,asp etc.) Session data (Standard ASP and PHP session data is stored locally by default!) 1) Your session data MUST be stored on a shared database Postgres, Oracle, MSSQL etc. 2) Your content either needs to be on shared storage, or replicated between each web server. On UNIX you can use the RSYNC command to replicate files, on Win2K you need ROBOCOPY from the NT resource kit. Usually you will FTP your content to one master server and then replicate it from there to the others. Now is also a great time to document the disaster recovery process for your web site, after all you do need to build two new web servers. What do you do if your application is not stateless? Re-write it! Seriously that's the best option, but if not don't worry just use persistence, you'll loose your fail over but you'll still get increased capacity. This problem occurs with all load balancers what ever the technology used to get around it. Persistence Methods The basic layer 4 persistence method is source IP persistence, you can handle millions of persistent connections at layer 4. NB. If you need to group HTTP & HTTPS as a persistent group you will need to use Firewall Marks (see the administration manual). What about the AOL mega proxy problem? You can change the persistence subnet mask to a lower granularity (which may help) or switch to layer 7 cookie based methods. NB. Obviously this won't work for any clients that don't accept cookies. Did we mention that you can't have fail over if you don't have persistence built into your application! Finalizing the network