03-linkproof tech training

87
Page 1 Radware LinkProof 5.11 Training 2007-09

Upload: mariamartinez7023

Post on 23-Aug-2014

221 views

Category:

Documents


37 download

TRANSCRIPT

Page 1: 03-LinkProof Tech Training

Page 1

Radware LinkProof

5.11 Training 2007-09

Page 2: 03-LinkProof Tech Training

Page 2

•Radware LinkProof 产品介绍•LinkProof 初始化安装与基本配置•双机配置•设备管理•售前方案设计

Agenda

Page 3: 03-LinkProof Tech Training

Page 3

Radware LinkProof Branch 平台产品介绍

LP Branch

•8 Fast Ethernet ports•25/50 Mbps throughput •64 MB RAM

Page 4: 03-LinkProof Tech Training

Page 4

Radware LinkProof AS 平台产品介绍

LP 100/200/202

• 8 Fast Ethernet ports• 2 Fiber SC GB ports• 200 Mbps throughput • 256 MB RAM

Page 5: 03-LinkProof Tech Training

Page 5

• 16 FE and 5 GBIC ports • 1000 Mbps throughput • 256 MB RAM

LP 1000

Radware LinkProof AS 平台产品介绍

Page 6: 03-LinkProof Tech Training

Page 6

• 12 Copper GB Ethernet ports• 8 GBIC ports• 3000 Mbps throughput • 512MB RAM

LP 3020

Radware LinkProof AS 平台产品介绍

Page 7: 03-LinkProof Tech Training

Page 7

Radware LinkProof ODS 平台产品介绍LP 108/208/1008/2008/4008 ODS VL

• 6 10/100/1000 Copper + 2SFP•100 Mbps throughput, 4 Gbps Max throughput•4GB RAM

Page 8: 03-LinkProof Tech Training

Page 8

Radware LinkProof ODS 平台产品介绍

LP 1016/2016/4016 ODS2

• 12 10/100/1000 Copper + 4 SFP• 1 Gbps throughput, 4 Gbps Max throughput•2GB RAM

Page 9: 03-LinkProof Tech Training

Page 9

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 10: 03-LinkProof Tech Training

Page 10

终端配置

Page 11: 03-LinkProof Tech Training

Page 11

初始化菜单

Page 12: 03-LinkProof Tech Training

Page 12

默认配置

Page 13: 03-LinkProof Tech Training

Page 13

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 14: 03-LinkProof Tech Training

Page 14

Web 管理登陆

默认用户名: radware

默认密码: radware

Page 15: 03-LinkProof Tech Training

Page 15

全局界面

Page 16: 03-LinkProof Tech Training

Page 16

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 17: 03-LinkProof Tech Training

Page 17

Link Aggregation

Radware devices support port trunking according to the IEEE 802.3ad standard for link aggregation. According to the IEEE 802.3ad standard:

• Link Aggregation is supported only on links using the IEEE 802.3 MAC • Link Aggregation is supported only on point-to-point links.

• Link Aggregation is supported only on links operating in full duplex mode. • Aggregation is permitted only among links with same speed and direction. On Radware devices bandwidth increments are provided in units of 100Mbps and 1Gbps respectively. • The failure or replacement of a single link within a Link Aggregation Group will not cause failure from the perspective of a MAC client.

Page 18: 03-LinkProof Tech Training

Page 18

Configuration

• Device > Link Aggregation > Port Table

Same Index

Page 19: 03-LinkProof Tech Training

Page 19

Port Table

Page 20: 03-LinkProof Tech Training

Page 20

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 21: 03-LinkProof Tech Training

Page 21

Assign IP Address

Ports number

• Router > IP Router > Interface Parameters > Create

Page 22: 03-LinkProof Tech Training

Page 22

Edit IP Address

Click to Edit

• Router > IP Router > Interface Parameters

Page 23: 03-LinkProof Tech Training

Page 23

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 24: 03-LinkProof Tech Training

Page 24

Add Route

Default Gateway:

Dest. Address

> 0.0.0.0

Network Mask

> 0.0.0.0

• Router > Routing Table > Create

Page 25: 03-LinkProof Tech Training

Page 25

Edit Routing Table

• Router > Routing Table

Click to Edit

Page 26: 03-LinkProof Tech Training

Page 26

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 27: 03-LinkProof Tech Training

Page 27

• A LinkProof farm is a group of networks servers that provide the same service. Servers contained in a server farm can belong to different vendors, or have a different capacity. The differences between the servers within a farm are transparent to the users. Providing all the servers within a group provide the same service managed by the LinkProof device, this group can be defined as a LinkProof server farm.

• When a new packet arrives that must be redirected to a certain farm, LinkProof selects the best server (according to user-defined criteria) from the servers available.

Terminology –Farm

Page 28: 03-LinkProof Tech Training

Page 28

The Virtual IP Farm (logical) servers represent applications residing on the physical server. Each application provides a particular service. LinkProof supports different farm server types, according to farm types: routers and firewalls.

The IP address of the farm server must also be defined. A physical server can have a few IP addresses, so different farm servers that are operating on the same physical server can have different IP addresses. The same Server Name and Server Address can be used in different farms (but same type of farms)

Farm Concept

Page 29: 03-LinkProof Tech Training

Page 29

Server Farm Basics

Main Farm

Subnet1 Farm

Subnet2 Farm

Page 30: 03-LinkProof Tech Training

Page 30

Farm Configuration

• LinkProof > Farms > Router Farm Table > Create

Name Smart Nat Persistency

Page 31: 03-LinkProof Tech Training

Page 31

Farm Parameters

Page 32: 03-LinkProof Tech Training

Page 32

Farm

Router 1 Router 2

LinkProof

LinkProof Dispatch Methods

•Cyclic (Round Robin)

•Weighted Cyclic (uses Round Robin but applies static weights assigned to servers)

•Least Traffic (in packets)

•Least Number of Users

•NT SNMP Parameters

•User-Configurable SNMP Parameters

•Hashing

•Response Time Load Balancing

Page 33: 03-LinkProof Tech Training

Page 33

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 34: 03-LinkProof Tech Training

Page 34

The Virtual IP Farm (logical) servers represent applications residing on the physical server. Each application provides a particular service. LinkProof supports different farm server types, according to farm types: routers and firewalls.

The IP address of the farm server must also be defined. A physical server can have a few IP addresses, so different farm servers that are operating on the same physical server can have different IP addresses. The same Server Name and Server Address can be used in different farms (but same type of farms)

Server Concept

Page 35: 03-LinkProof Tech Training

Page 35

Server Maintenance

• LinkProof > Servers > Logic Routers Table > Create

Gateway

Name

Page 36: 03-LinkProof Tech Training

Page 36

Server Maintenance

Same Farm NameLoadbalance:

Different Gateway

Default Loadbalance Farm&Servers

Page 37: 03-LinkProof Tech Training

Page 37

Server Weights allow administrators to take into account equipment that has greater (or lesser) capacity than other servers in the same farm.

LinkProof

Weight = 1 Weight = 1

Weight = 5

Server Management - Weights

Page 38: 03-LinkProof Tech Training

Page 38

Server Management – Operational Mode

Local Network

Active

LinkProof

Active Backup

Page 39: 03-LinkProof Tech Training

Page 39

Server Management – Connection Limit

Connection Limit is the maximum number of users that can be directed to a server for a service provided by the farm. The number of users depends on the Sessions Mode, because it is determined by the number of active entries in the Client Table for sessions destined to the specific server.

Page 40: 03-LinkProof Tech Training

Page 40

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 41: 03-LinkProof Tech Training

Page 41

Flow Concept

• LinkProof 5.xx uses flow policies instead of Groupings (in previous versions)

• Multiple farms can contain the same or different routers• Policies are configured based on source, destination,

application, content, etc. to send traffic through routers in a particular farm

• Routers can be active or backup within a farm• Administrators can configure the LinkProof to redirect

specific kinds of traffic to specific devices or groups of devices. This feature is based on the concept of Flows, introduced in version 5.10 and can be done based on the destination port, destination IP address, source IP address, or combinations

Page 42: 03-LinkProof Tech Training

Page 42

Flow Definitions

Main Farm

Subnet1 Farm

Subnet2 Farm

Flow 1 – Use Subnet1 Farm

Flow 2 – Use Subnet2 Farm

Page 43: 03-LinkProof Tech Training

Page 43

Flow Policies

Main Farm

Subnet1 Farm

Subnet2 Farm

Source = Subnet1 Source = Subnet2

Flow Policy:Source = Subnet1

Flow = Subnet1 Farm

Flow Policy:Source = Subnet2

Flow = Subnet2 Farm

Page 44: 03-LinkProof Tech Training

Page 44

Flow Policies for Application

•Main Farm contains both routers•Web Farm contains router 1•FTP Farm contains router 2

Main Farm

Web Farm

FTPFarm

FTP Flow:Use FTP

Farm

Web Flow:Use Web

Farm

Page 45: 03-LinkProof Tech Training

Page 45

Flow Policies for Application

Main Farm

Web Farm

FTPFarm

Flow Policy:HTTP Flow = Use Web Farm

Flow Policy:FTP Flow = Use FTP Farm

HTTP FTP

Page 46: 03-LinkProof Tech Training

Page 46

Flow Table

• LinkProof > Flow Management > Farm Flow Table > Create

Default FarmDefault Flow

Page 47: 03-LinkProof Tech Training

Page 47

Flow Table

• LinkProof > Flow Management > Farm Flow Table > Create

Flow Index

Select Farm

Page 48: 03-LinkProof Tech Training

Page 48

Flow Table

• LinkProof > Flow Management > Farm Flow Table > Create

Page 49: 03-LinkProof Tech Training

Page 49

Flow Policy

• LinkProof > Flow Management > Modify Policies > Create

Page 50: 03-LinkProof Tech Training

Page 50

Flow Policy

Name Little number will be executed first

Classes-Networks

Especial Flow

LinkProof > Flow Management >Update Policies

Page 51: 03-LinkProof Tech Training

Page 51

Client Management

• Client Table tracks all outbound and inbound client sessions along with the router selected

• Default aging time is 60 seconds• After 60 seconds of inactivity, a given entry is dropped• Aging time can be set per router farm• Application Aging can be set in global

Page 52: 03-LinkProof Tech Training

Page 52

Client Table CLI

Client Table current entries can be viewed via CLI only using thefollowing commands:• lp client table (to see client table information)• lp client table-summary (to see summary information)• lp client clear (clear client table)The following options are available with the lp client table CLIcommand, which allow you to filter existing client entries and display only relevant entries:• -ip to print only entries with given IP address• -fl to print only entries with given flow name• -fn to print only entries with given farm name• -sn to print only entries with given server name• -vl to print only entries with forwarding type bridging• -ap to print only entries with given application port• -db to print only entries with delayed binding information• -ed to print only entries with edge farm info• -mapped to print entries including mapped information• -ptr to print only entries with given packet translation type (VIP,Dynamic NAT, VPN, etc).

Page 53: 03-LinkProof Tech Training

Page 53

Aging By Application

LinkProof

Flow 2Flow 1

Web Traffic

Telnet Traffic

DNS Traffic

HTTPS Traffic

Client Table Default = 60

Port 80 Aging = 30 secondsPort 23 Aging = 600 secondsPort 53 Aging = 10 secondsPort 443 Aging = 1200 seconds

Page 54: 03-LinkProof Tech Training

Page 54

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 55: 03-LinkProof Tech Training

Page 55

Dynamic SmartNAT

The LinkProof uses Dynamic SmartNAT to route traffic from internal resources out the available Next-Hop-Routers. This is a Many-to-One translation

Local User

NHR11.1.1.100

LinkProof

NHR22.2.2.200

SmartNAT with 1.1.1.150

SmartNAT with 2.2.2.250

Page 56: 03-LinkProof Tech Training

Page 56

Static SmartNAT – cont.

Static SmartNAT addresses are also used to present a public address through each available router that can be used to access an internal resource

Server

NHR11.1.1.100

LinkProofNHR2

2.2.2.200 Client

SmartNAT for Server = 1.1.1.10

SmartNAT for Server = 2.2.2.20

Page 57: 03-LinkProof Tech Training

Page 57

Basic SmartNAT

Basic SmartNAT can be used for outbound user traffic when an application’s source port must be preserved – uses a pool.

NHR11.1.1.100

LinkProofNHR2

2.2.2.200

User 1

User 3

User 2

Application

NAT with 1.1.1.20

NAT with 2.2.2.20

NAT with 1.1.1.21

NAT with 1.1.1.21

Page 58: 03-LinkProof Tech Training

Page 58

No NAT

In some cases, it may not make sense to have the LinkProof perform NAT for hosts on a public network or behind a firewall performing NAT.

ServersNHR1

1.1.1.100

LinkProof

NHR22.2.2.200

1.1.1.111

1.1.1.112

1.1.1.113

No NAT – Source Preserved

NAT with Address from 2.2.2.0

Page 59: 03-LinkProof Tech Training

Page 59

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 60: 03-LinkProof Tech Training

Page 60

Modify Classes

• Classes > Modify Networks > Create

Same Name Differ Index

LinkProof > Classes >Update Policies

Page 61: 03-LinkProof Tech Training

Page 61

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 62: 03-LinkProof Tech Training

Page 62

Inbound

• The LinkProof can shape inbound traffic to internal hosts (web, ftp, application hosts, etc.) by answering DNS queries for specific hosts

• The LinkProof will answer queries with an appropriate Static NAT address from an available router network

• Clients can then access the internal host by connecting to the Static NAT address they receive

• For increase performance it is recommended to configure the DNS servers (When user configure DNS Servers Table, Link Proof will check the given DNS servers reply only)

Page 63: 03-LinkProof Tech Training

Page 63

Inbound Configuration

Select Internal

1:Static Nat

2:Name To Local IP

• LinkProof > DNS Configuration > DNS for Local Clients

Page 64: 03-LinkProof Tech Training

Page 64

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 65: 03-LinkProof Tech Training

Page 65

Proximity Concept

The proximity probes are a combination of IP, TCP, and application layer probes (such as TCP ACK's and ICMP Echo requests) to ensureaccurate measurements. The type of checks used for proximity is configurable to allow users more control of the device and generate maximum performance fromthe links.

Page 66: 03-LinkProof Tech Training

Page 66

Proximity Configuration

• LinkProof > Proximity

Page 67: 03-LinkProof Tech Training

Page 67

• RADWARE LinkProof 产品介绍• LinkProof 初始化安装与基本配置 1, LinkProof- 配置 - 初始化 2, LinkProof- 配置 -Network 3, LinkProof- 配置 -PortChannel 4, LinkProof- 配置 -Interface 5, LinkProof- 配置 -Route 6, LinkProof- 配置 -Farm 7, LinkProof- 配置 -Server 8, LinkProof- 配置 -Flow 9, LinkProof- 配置 -Nat

10, LinkProof- 配置 -Classes11, LinkProof- 配置 -Inbound12, LinkProof- 配置 -Proximity13, LinkProof- 配置 -Tuning

• 双机配置• 设备管理

Page 68: 03-LinkProof Tech Training

Page 68

Tuning

• Services > Tuning > Device > General

Page 69: 03-LinkProof Tech Training

Page 69

LinkProof 配置总结• 确认部署环境及 IP 规划• 配置 Interface IP、 Router

• 配置 Farm

• 配置 Server ,并加入相应Farm

• 配置 Flow Policy

• 配置 NAT

• 配置 Health Monitor

• Device Tuning

Page 70: 03-LinkProof Tech Training

Page 70

•Radware LinkProof 产品介绍•LinkProof 初始化安装与基本配置•双机配置•设备管理•售前方案设计

Page 71: 03-LinkProof Tech Training

Page 71

• Radware devices should be employed in pairs for fault-tolerance and fail-over

• Two methods available for redundancy:Proprietary (using ARP)VRRP (RFC:2338 Virtual Router Redundancy Protocol)

Redundancy

Page 72: 03-LinkProof Tech Training

Page 72

•Radware LinkProof 产品介绍•LinkProof 初始化安装与基本配置•双机配置•设备管理•售前方案设计

Page 73: 03-LinkProof Tech Training

Page 73

LinkProof Management Methods

Management Methods Available:

• APSolute Insite

• Telnet / SSH

• Web Based Interface / Secure Web

• Serial Command Line Interface

• SNMP

Page 74: 03-LinkProof Tech Training

Page 74

LinkProof Monitoring – Web

• Device > Device Monitoring

Page 75: 03-LinkProof Tech Training

Page 75

LinkProof Configurations Save/Upload

• File > Configuration >Receive From Device/Send to Device

Page 76: 03-LinkProof Tech Training

Page 76

Event Notifications can be received via the following methods

• Syslog

• Email

• Serial connection traps

• SNMP Traps

LinkProof Notification

Page 77: 03-LinkProof Tech Training

Page 77

Access to the Device can be limited in several ways:

• SNMP Community strings (for AP insite)

• Username and password (for Telnet and WBM)

• Management method restricts per physical interface (i.e. WBM and SNMP through port 2 and SSH only through port 1)

• Radius Server Authentication

LinkProof Management Permissions

Page 78: 03-LinkProof Tech Training

Page 78

LinkProof Security – Web

• Device Security > User > Create or Edit

Page 79: 03-LinkProof Tech Training

Page 79

hardware

lp-as1-3_73_11.bin

product version

LinkProof Software Version

Page 80: 03-LinkProof Tech Training

Page 80

Upgrade Firmware

• File > Software Upgrade

Page 81: 03-LinkProof Tech Training

Page 81

•Radware LinkProof 产品介绍•LinkProof 初始化安装与基本配置•双机配置•设备管理•售前方案设计

Page 82: 03-LinkProof Tech Training

Page 82

LinkProof 售前方案设计

• 熟悉了解客户网络• 了解详细需求,设备选型 (选型时充分考虑销售需求、对手情况)• 方案设计 (包括 IP 规划、割接步骤、回退措施)

Page 83: 03-LinkProof Tech Training

Page 83

售前案例分析 – 用户现状

接入路由器A 接入路由器B

防火墙 防火墙

核心交换机 核心交换机

网通50M 网通100M 网通100M政务外网50M文献中心

科技网教育网 中央党校 IPV6

汇聚层和接入层网络

Page 84: 03-LinkProof Tech Training

Page 84

售前案例分析 – 用户需求

1、考虑到业务特点 ,在尽量减少对现网业务影响的情况下,链路负载均衡方案可考虑分布实施。 2、链路负载均衡方案应能够智能利用多条链路资源,既能屏蔽跨运营商之间的网络限制,又能充分利用多条互联网链路资源,来保证链路的高可靠性和应用系统的访问效率。 3、实现进( Inbound )出( Outbound )双向流量在多广域网链路出口情况下的智能管理。保障公众用户以最佳的途径访问到内部系统,以及应用服务器的响应数据最快速的返回用户端。

Page 85: 03-LinkProof Tech Training

Page 85

售前案例分析 – 过渡方案设计网通网通 网通

1G

100M 50M 100M

Router A Router B

电信

文献中心

政务外网教育网

党校

linkproof

50M

Page 86: 03-LinkProof Tech Training

Page 86

网通网通 网通

1G

100M 50M100M

Router A Router B

电信

文献中心

政务外网教育网

党校

50M

linkproof linkproof

售前案例分析 – 最终方案设计

Page 87: 03-LinkProof Tech Training

Page 87