ããŒã1 å ¥é
ããŒã2 ãã¡ã€ã¢ãŠã©ãŒã«ãšNATã«ãŒã«ãæ§æãã
ããŒã3ã DHCPã»ããã¢ãã
ããŒã4 ã«ãŒãã£ã³ã°èšå®
ååãéçã«ãŒãã£ã³ã°ãšåçã«ãŒãã£ã³ã°ã®èŠ³ç¹ããNSX Edgeã®æ©èœã«ã€ããŠè©±ããŸããããä»æ¥ã¯ãã©ã³ãµãŒãæ±ããŸãã
ã»ããã¢ãããé²ããåã«ããã©ã³ã¹ã®äž»ãªã¿ã€ããç°¡åã«æãåºããããšæããŸãã
çè«
ä»æ¥ã®ãã¹ãŠã®ãã€ããŒããã©ã³ã·ã³ã°ãœãªã¥ãŒã·ã§ã³ã¯ãã»ãšãã©ã®å Žåã OSIã¢ãã«ã®ç¬¬4ïŒãã©ã³ã¹ããŒãïŒã¬ãã«ãšç¬¬7ïŒé©çšïŒã¬ãã«ã®ãã©ã³ã·ã³ã°ãšãã2ã€ã®ã«ããŽãªã«åé¡ãããŸãã OSIã¢ãã«ã¯ããã©ã³ã¹æ¹æ³ã説æããéã®æè¯ã®åºæºç¹ã§ã¯ãããŸããã ããšãã°ãL4ãã©ã³ãµãŒãTLSçµç«¯ããµããŒãããŠããå ŽåãL7ãã©ã³ãµãŒã«ãªããŸããïŒ ããããããã¯ããã§ãã
- L4ãã©ã³ãµãŒã¯ãã»ãšãã©ã®å Žåãã¯ã©ã€ã¢ã³ããšå©çšå¯èœãªäžéãããã·ããã¯ãšã³ãã®ã»ããã®éã«ãããTCPæ¥ç¶ãçµäºããŸãïŒã€ãŸããSYNã«ç¬ç«ããŠå¿çããŸãïŒãããã¯ãšã³ããéžæãããã®æ¹åã§æ°ããTCPã»ãã·ã§ã³ãéå§ããSYNèªäœãéä¿¡ããŸãã ãã®ã¿ã€ãã¯åºæ¬çãªãã®ã®1ã€ã§ãããä»ã®ãªãã·ã§ã³ãå¯èœã§ãã
- L7ãã©ã³ãµãŒã¯ãL4ãã©ã³ãµãŒããããé«åºŠãªãå©çšå¯èœãªããã¯ãšã³ãã«ãã©ãã£ãã¯ãåæ£ããŸãã 圌ã¯ãããšãã°HTTPã¡ãã»ãŒãžã®å 容ïŒURLãCookieãªã©ïŒã«åºã¥ããŠããã¯ãšã³ãã決å®ã§ããŸãã
ã¿ã€ãã«é¢ä¿ãªãããã©ã³ãµãŒã¯æ¬¡ã®æ©èœããµããŒãã§ããŸãã
- ãµãŒãã¹ãã£ã¹ã«ããªã¯ãå©çšå¯èœãªããã¯ãšã³ãïŒéçãDNSãConsulãEtcdãªã©ïŒã®ã»ããã決å®ããããã»ã¹ã§ãã
- æ€åºãããããã¯ãšã³ãã®å¥å šæ§ã®ãã§ãã¯ïŒHTTPèŠæ±ã䜿çšããããã¯ãšã³ãã®ã¢ã¯ãã£ããªãpingããTCPæ¥ç¶ã®åé¡ã®ååçæ€åºãé£ç¶ããåçã®ããã€ãã®503 HTTPã³ãŒãã®ååšãªã©ïŒã
- ããèªäœã®ãã©ã³ã¹ïŒã©ãŠã³ãããã³ãã©ã³ãã éžæããœãŒã¹IPããã·ã¥ãURIïŒã
- TLSã®çµäºãšèšŒææžã®æ€èšŒã
- ã»ãã¥ãªãã£é¢é£ã®ãªãã·ã§ã³ïŒèªèšŒãDoSæ»æã®é²æ¢ãå¶éé床ïŒãªã©ã
NSX Edgeã¯ã2ã€ã®ãã©ã³ãµãŒå±éã¢ãŒãããµããŒãããŠããŸãã
ãããã·ã¢ãŒãããŸãã¯ã¯ã³ã¢ãŒã ã ãã®ã¢ãŒãã§ã¯ãNSX Edgeã¯ãããã¯ãšã³ãã®1ã€ã«ãªã¯ãšã¹ããéä¿¡ãããšãã«ããã®IPã¢ãã¬ã¹ããœãŒã¹ã¢ãã¬ã¹ãšããŠäœ¿çšããŸãã ãããã£ãŠããã©ã³ãµãŒã¯éä¿¡å ãšå®å ã®äž¡æ¹ã®NATæ©èœãå®è¡ããŸãã ããã¯ãšã³ãã¯ããã©ã³ãµãŒããéä¿¡ããããã¹ãŠã®ãã©ãã£ãã¯ã確èªããããã«çŽæ¥å¿çããŸãã ãã®ã¹ããŒã ã§ã¯ããã©ã³ãµãŒã¯å éšãµãŒããŒãšåããããã¯ãŒã¯ã»ã°ã¡ã³ãã«ååšããå¿ èŠããããŸãã
æ¹æ³ã¯æ¬¡ã®ãšããã§ãã
- ãŠãŒã¶ãŒã¯ãEdgeã§æ§æãããŠããVIPã¢ãã¬ã¹ïŒãã©ã³ãµãŒã¢ãã¬ã¹ïŒã«èŠæ±ãéä¿¡ããŸãã
- Edgeã¯ããã¯ãšã³ãã®1ã€ãéžæããå®å NATãå®è¡ããŠãVIPã¢ãã¬ã¹ãéžæããããã¯ãšã³ãã®ã¢ãã¬ã¹ã«çœ®ãæããŸãã
- Edgeã¯ãœãŒã¹NATãå®è¡ãããªã¯ãšã¹ããéä¿¡ãããŠãŒã¶ãŒã®ã¢ãã¬ã¹ãç¬èªã®ã¢ãã¬ã¹ã«çœ®ãæããŸãã
- ãã±ããã¯éžæããããã¯ãšã³ãã«éä¿¡ãããŸãã
- ãŠãŒã¶ãŒã®å ã®ã¢ãã¬ã¹ããã©ã³ãµãŒã®ã¢ãã¬ã¹ã«å€æŽããããããããã¯ãšã³ãã¯ãŠãŒã¶ãŒã«çŽæ¥å¿çããŸãããããšããžã«å¿çããŸãã
- Edgeã¯ãµãŒããŒã®å¿çããŠãŒã¶ãŒã«éä¿¡ããŸãã
以äžã®ã¹ããŒã ã
ééã¢ãŒããŸãã¯ã€ã³ã©ã€ã³ã¢ãŒãã ãã®ã·ããªãªã§ã¯ããã©ã³ãµãŒã®å éšããã³å€éšãããã¯ãŒã¯ã«ã€ã³ã¿ãŒãã§ãŒã¹ããããŸãã ãã ããå€éšããå éšãããã¯ãŒã¯ãžã®çŽæ¥ã¢ã¯ã»ã¹ã¯ãããŸããã çµã¿èŸŒã¿ã®ããŒããã©ã³ãµãŒã¯ãå éšãããã¯ãŒã¯äžã®ä»®æ³ãã·ã³ã®NATã²ãŒããŠã§ã€ãšããŠæ©èœããŸãã
ã¡ã«ããºã ã¯æ¬¡ã®ãšããã§ãã
- ãŠãŒã¶ãŒã¯ãEdgeã§æ§æãããŠããVIPã¢ãã¬ã¹ïŒãã©ã³ãµãŒã¢ãã¬ã¹ïŒã«èŠæ±ãéä¿¡ããŸãã
- Edgeã¯ããã¯ãšã³ãã®1ã€ãéžæããå®å NATãå®è¡ããŠãVIPã¢ãã¬ã¹ãéžæããããã¯ãšã³ãã®ã¢ãã¬ã¹ã«çœ®ãæããŸãã
- ãã±ããã¯éžæããããã¯ãšã³ãã«éä¿¡ãããŸãã
- ããã¯ãšã³ãã¯ããŠãŒã¶ãŒã®å ã®ã¢ãã¬ã¹ïŒãœãŒã¹NATã¯å®è¡ãããŸããã§ããïŒãå«ãèŠæ±ãåä¿¡ããããã«çŽæ¥å¿çããŸãã
- ã€ã³ã©ã€ã³ã¹ããŒã ã§ã¯éåžžããµãŒããŒãã¡ãŒã ã®ããã©ã«ãã²ãŒããŠã§ã€ãšããŠæ©èœããããããã©ãã£ãã¯ã¯ããŒããã©ã³ãµãŒã«ãã£ãŠåã³åãå ¥ããããŸãã
- ãšããžã¯ãœãŒã¹NATãå®è¡ããŠãVIPããœãŒã¹IPã¢ãã¬ã¹ãšããŠäœ¿çšããŠããŠãŒã¶ãŒã«ãã©ãã£ãã¯ãéä¿¡ããŸãã
以äžã®ã¹ããŒã ã
ç·Žç¿ãã
ç§ã®ãã¹ããã³ãã§ã¯ãApacheãåãã3å°ã®ãµãŒããŒãæ§æãããŠãããHTTPSã§åäœããããã«æ§æãããŠããŸãã Edgeã¯ã©ãŠã³ãããã³æ¹åŒã䜿çšããŠHTTPSèŠæ±ã®ãã©ã³ã¹ãåããæ°ããèŠæ±ãæ°ãããµãŒããŒã«ãããã·ããŸãã
å§ããŸãããã
NSX Edgeã䜿çšããSSL蚌ææžã®çæ
æå¹ãªCA蚌ææžãã€ã³ããŒãããããèªå·±çœ²å蚌ææžã䜿çšã§ããŸãã ãã®ãã¹ãã§ã¯ãèªå·±çœ²åã䜿çšããŸãã
- vCloud Directorã€ã³ã¿ãŒãã§ã€ã¹ã§ãEdgeãµãŒãã¹ã®èšå®ã«ç§»åããŸãã
- [蚌ææž]ã¿ãã«ç§»åããŸãã ã¢ã¯ã·ã§ã³ã®ãªã¹ããããæ°ããCSRã®è¿œå ãéžæããŸãã
- å¿
é ãã£ãŒã«ãã«å
¥åããŠã[ä¿æ]ãã¯ãªãã¯ããŸãã
- æ°ããäœæãããCSRãéžæããèªå·±çœ²åCSRãªãã·ã§ã³ãéžæããŸãã
- 蚌ææžã®æå¹æéãéžæããŠã[ä¿æ]ãã¯ãªãã¯ããŸã
- å©çšå¯èœãªãªã¹ãã«èªå·±çœ²å蚌ææžã衚瀺ãããŸããã
ã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«ã®æ§æ
ã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«ã䜿çšãããšããããã¯ãŒã¯ãã©ãã£ãã¯ããã现ããå¶åŸ¡ã§ãã管çãç°¡åãã€å¹ççã«ãªããŸãã 圌ãã®å©ããåããŠãç¹å®ã®çš®é¡ã®ãã©ãã£ãã¯ã®åäœãå€æã§ããŸãã
- [ããŒããã©ã³ãµãŒ]ã¿ãã«ç§»åãããã©ã³ãµãŒããªã³ã«ããŸãã ããã§ã®Accelerated enabledãªãã·ã§ã³ã¯ããã©ã³ãµãŒãL7ã®ä»£ããã«é«éã®L4ãã©ã³ã·ã³ã°ã䜿çšã§ããããã«ããŸãã
- [ã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«]ã¿ãã«ç§»åããŠãã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«ãèšå®ããŸãã +ãã¯ãªãã¯ããŸãã
- ãããã¡ã€ã«åãèšå®ãããããã¡ã€ã«ãé©çšããããã©ãã£ãã¯ã®ã¿ã€ããéžæããŸãã ããã€ãã®ãã©ã¡ãŒã¿ãŒã«ã€ããŠèª¬æããŸãã
æ°žç¶æ§ -ã»ãã·ã§ã³ããŒã¿ãä¿åããã³è¿œè·¡ããŸããããšãã°ãããŒã«ã®ã©ã®ç¹å®ã®ãµãŒããŒããŠãŒã¶ãŒãªã¯ãšã¹ããåŠçããŠããŸããã ããã«ãããã»ãã·ã§ã³ãŸãã¯ãã以éã®ã»ãã·ã§ã³ã®åç¶æéäžããŠãŒã¶ãŒèŠæ±ãåãããŒã«ã¡ã³ããŒã«éä¿¡ãããŸãã
SSLãã¹ã¹ã«ãŒãæå¹ã«ãã -ãã®ãªãã·ã§ã³ãéžæãããšãNSX Edgeã¯SSLã®çµäºãåæ¢ããŸãã 代ããã«ããã©ã³ã·ã³ã°ãå®è¡ããããµãŒããŒã§çŽæ¥çµäºãçºçããŸãã
X-Forwarded-For HTTPããããŒã®æ¿å ¥ -ãã©ã³ãµãŒãä»ããŠWebãµãŒããŒã«æ¥ç¶ããã¯ã©ã€ã¢ã³ãã®ãœãŒã¹IPã¢ãã¬ã¹ã決å®ã§ããŸãã
ããŒã«åŽã®SSLãæå¹ã«ãã-éžæããããŒã«ãHTTPSãµãŒããŒã§æ§æãããããšãæå®ã§ããŸãã
- HTTPSãã©ãã£ãã¯ã®ãã©ã³ã¹ããšãã®ã§ãããŒã«ãµã€ãSSLãæå¹ã«ããä»®æ³ãµãŒããŒèšŒææž->ãµãŒãã¹èšŒææžã¿ãã§ä»¥åã«çæããã蚌ææžãéžæããå¿
èŠããããŸãã
- ããŒã«èšŒææž->ãµãŒãã¹èšŒææžã«ã€ããŠãåæ§ã§ãã
ãµãŒããŒã®ããŒã«ãäœæããããŒã«ã®ãã©ã³ã¹ããšããââã©ãã£ãã¯
- [ããŒã«]ã¿ãã«ç§»åããŸãã +ãã¯ãªãã¯ããŸãã
- ããŒã«åãèšå®ããã¢ã«ãŽãªãºã ïŒã©ãŠã³ãããã³ã䜿çšããŸãïŒããã³ããã¯ãšã³ãã®ãã«ã¹ãã§ãã¯ã®ç£èŠã¿ã€ããéžæããŸãééãªãã·ã§ã³ã¯ãåæãœãŒã¹IPã¯ã©ã€ã¢ã³ããå
éšãµãŒããŒã«è¡šç€ºããããã©ããã瀺ããŸãã
- ãã®ãªãã·ã§ã³ãç¡å¹ã«ãããšãå
éšãµãŒããŒã®ãã©ãã£ãã¯ã¯ãã©ã³ãµãŒã®ãœãŒã¹IPããéä¿¡ãããŸãã
- ãã®ãªãã·ã§ã³ãæå¹ãªå Žåãå éšãµãŒããŒã¯ãœãŒã¹IPã¯ã©ã€ã¢ã³ããåç §ããŸãã ãã®æ§æã§ã¯ãNSX Edgeãããã©ã«ãã²ãŒããŠã§ã€ãšããŠæ©èœããè¿ããããã±ãããNSX Edgeãééããããã«ããå¿ èŠããããŸãã
NSXã¯ã次ã®ãã©ã³ã·ã³ã°ã¢ã«ãŽãªãºã ããµããŒãããŠããŸãã
- IP_HASH-åãã±ããã®éä¿¡å ããã³å®å IPã®ããã·ã¥é¢æ°ã®çµæã«åºã¥ããµãŒããŒã®éžæã
- LEASTCONN-ç¹å®ã®ãµãŒããŒã§æ¢ã«å©çšå¯èœãªæ°ã«å¿ããŠãçä¿¡æ¥ç¶ã®ãã©ã³ã¹ããšããŸãã æ°ããæ¥ç¶ã¯ãæ¥ç¶ã®æ°ãæãå°ãªããµãŒããŒã«åããããŸãã
- ROUND_ROBIN-æ°ããæ¥ç¶ã¯ãæå®ãããéã¿ã«åŸã£ãŠåãµãŒããŒã«é çªã«éä¿¡ãããŸãã
- URI - URIã®å·ŠéšåïŒçå笊ã®åïŒã¯ããã·ã¥ãããããŒã«å ã®ãµãŒããŒã®ç·ééã§é€ç®ãããŸãã çµæã¯ãã©ã®ãµãŒããŒããªã¯ãšã¹ããåä¿¡ãããã瀺ãããã¹ãŠã®ãµãŒããŒãå©çšå¯èœã§ããéãããªã¯ãšã¹ããåžžã«åããµãŒããŒã«ã«ãŒãã£ã³ã°ãããããã«ããŸãã
- HTTPHEADER-ãã©ã¡ãŒã¿ãŒãšããŠæå®ã§ããç¹å®ã®HTTPããããŒã«åºã¥ããã©ã³ã¹ã ããããŒãæ¬ èœããŠããããæå³ããªãå ŽåãROUND_ROBINã¢ã«ãŽãªãºã ã䜿çšãããŸãã
- URL-åHTTP GETãªã¯ãšã¹ãã¯ãåŒæ°ãšããŠæå®ãããURLãã©ã¡ãŒã¿ãŒãæ€çŽ¢ããŸãã ãã©ã¡ãŒã¿ãŒã®åŸã«çå·ãšå€ãç¶ãå Žåãå€ã¯ããã·ã¥ãããå®è¡äžã®ãµãŒããŒã®ç·ééã§é€ç®ãããŸãã çµæã¯ããªã¯ãšã¹ããåä¿¡ãããµãŒããŒã瀺ããŸãã ãã®ããã»ã¹ã¯ããã¹ãŠã®ãµãŒããŒã䜿çšå¯èœã§ããéããèŠæ±å ã®ãŠãŒã¶ãŒIDã远跡ããåããŠãŒã¶ãŒIDãåžžã«åããµãŒããŒã«éä¿¡ãããããã«ããããã«äœ¿çšãããŸãã
- ãã®ãªãã·ã§ã³ãç¡å¹ã«ãããšãå
éšãµãŒããŒã®ãã©ãã£ãã¯ã¯ãã©ã³ãµãŒã®ãœãŒã¹IPããéä¿¡ãããŸãã
- [ã¡ã³ããŒ]ãããã¯ã§[+]ãã¯ãªãã¯ããŠããµãŒããŒãããŒã«ã«è¿œå ããŸãã
ããã§æå®ããå¿ èŠããããŸãïŒ
- ãµãŒããŒå
- ãµãŒããŒã®IPã¢ãã¬ã¹ã
- ãµãŒããŒããã©ãã£ãã¯ãåä¿¡ããããŒãã
- ãã«ã¹ãã§ãã¯çšã®ããŒãïŒãã«ã¹ãã§ãã¯ã®ç£èŠïŒ;
- éã¿-ãã®ãã©ã¡ãŒã¿ãŒã䜿çšãããšãããŒã«ã®ç¹å®ã®ã¡ã³ããŒã®åä¿¡ãã©ãã£ãã¯ã®æ¯äŸéã調æŽã§ããŸãã
- æ倧æ¥ç¶æ°-ãµãŒããŒãžã®æ¥ç¶ã®æ倧æ°ã
- æå°æ¥ç¶æ°-ãã©ãã£ãã¯ã次ã®ããŒã«ã¡ã³ããŒã«ãªãã€ã¬ã¯ããããåã«ãµãŒããŒãåŠçããå¿ èŠãããæå°æ¥ç¶æ°ã
ããã¯ã3å°ã®ãµãŒããŒã®æçµçãªããŒã«ã®ããã§ãã
ä»®æ³ãµãŒããŒãè¿œå
- [ä»®æ³ãµãŒããŒ]ã¿ãã«ç§»åããŸãã +ãã¯ãªãã¯ããŸãã
- Enable Virtual Serverã䜿çšããŠä»®æ³ãµãŒããŒãã¢ã¯ãã£ãåããŸãã
ååãä»ãã以åã«äœæããã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«ãããŒã«ãéžæããä»®æ³ãµãŒããŒãå€éšããã®èŠæ±ãåãå ¥ããIPã¢ãã¬ã¹ãæå®ããŸãã HTTPSãããã³ã«ãšããŒã443ãæå®ããŸãã
ããã®ãªãã·ã§ã³ã®ãã©ã¡ãŒã¿ãŒïŒ
æ¥ç¶å¶é -ä»®æ³ãµãŒããŒãåŠçã§ããåææ¥ç¶ã®æ倧æ°ã
æ¥ç¶ã¬ãŒãå¶éïŒCPSïŒ-1ç§ãããã®æ°ããçä¿¡èŠæ±ã®æ倧æ°ã
ããã§ãã©ã³ãµãŒã®èšå®ãå®äºããããã©ãŒãã³ã¹ã確èªã§ããŸãã ãµãŒããŒã«ã¯æãåçŽãªæ§æããããããŒã«ã®ã©ã®ãµãŒããŒããªã¯ãšã¹ããåŠçããããææ¡ã§ããŸãã ã»ããã¢ããäžã«ã©ãŠã³ãããã³ãã©ã³ã·ã³ã°ã¢ã«ãŽãªãºã ãéžæããŸãããåãµãŒããŒã®Weightãã©ã¡ãŒã¿ãŒã¯1ã«çããããã次ã®åèŠæ±ã¯ããŒã«ã®æ¬¡ã®ãµãŒããŒã«ãã£ãŠåŠçãããŸãã
ãã©ãŠã¶ã«ãã©ã³ãµãŒã®å€éšã¢ãã¬ã¹ãå ¥åããŠã以äžãåç §ããŠãã ããã
ããŒãžãæŽæ°ããåŸããªã¯ãšã¹ãã¯æ¬¡ã®ãµãŒããŒã«ãã£ãŠåŠçãããŸãã
ãããŠåã³-ããŒã«ãã3çªç®ã®ãµãŒããŒããã§ãã¯ããã«ã¯ïŒ
ãã§ãã¯ãããšãEdgeãéä¿¡ãã蚌ææžãæåã«çæãããã®ãšåãã§ããããšãããããŸãã
Edgeã²ãŒããŠã§ã€ã³ã³ãœãŒã«ãããã©ã³ãµãŒã®ã¹ããŒã¿ã¹ã確èªããŸãã ãããè¡ãã«ã¯ã show service loadbalancer poolãšå ¥åããŸã ã
ããŒã«å ã®ãµãŒããŒã®ã¹ããŒã¿ã¹ã確èªããããã®Service Monitorã®æ§æ
Service Monitorã䜿çšããŠãããã¯ãšã³ãããŒã«å ã®ãµãŒããŒã®ã¹ããŒã¿ã¹ãç£èŠã§ããŸãã èŠæ±ãžã®å¿çãäºæãããã®ãšäžèŽããªãå ŽåããµãŒããŒã¯ããŒã«ããæ€åããŠãæ°ããèŠæ±ãåãåããªãããã«ããããšãã§ããŸãã
ããã©ã«ãã§ã¯ã3ã€ã®æ€èšŒæ¹æ³ãèšå®ãããŠããŸãã
- TCPã¢ãã¿ãŒ
- HTTPã¢ãã¿ãŒ
- HTTPSã¢ãã¿ãŒã
æ°ãããã®ãäœæããŸãã
- [ãµãŒãã¹ã®ç£èŠ]ã¿ãã«ç§»åãã[+]ãã¯ãªãã¯ããŸãã
- éžæããŠãã ããïŒ
- æ°ããã¡ãœããã®ååã
- ãªã¯ãšã¹ããéä¿¡ãããééã
- å¿çã¿ã€ã ã¢ãŠã
- ç£èŠã¿ã€ãã¯GETã¡ãœããã䜿çšããHTTPSèŠæ±ã§ãããäºæ³ãããã¹ããŒã¿ã¹ã³ãŒãã¯200ïŒOKïŒã§ãããèŠæ±URLã§ãã
- ããã§æ°ããService Monitorã®æ§æãå®äºããããŒã«ãäœæãããšãã«äœ¿çšã§ããããã«ãªããŸããã
ã¢ããªã±ãŒã·ã§ã³ã«ãŒã«ãæ§æãã
ã¢ããªã±ãŒã·ã§ã³ã«ãŒã«ã¯ãç¹å®ã®ããªã¬ãŒã«åºã¥ããŠãã©ãã£ãã¯ãæäœããæ¹æ³ã§ãã ãã®ããŒã«ã䜿çšããŠãé«åºŠãªè² è·åæ£ã«ãŒã«ãäœæã§ããŸããããã¯ãã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«ãŸãã¯Edge Gatewayã§å©çšå¯èœãªä»ã®ãµãŒãã¹ã䜿çšããŠæ§æã§ããªãå ŽåããããŸãã
- ã«ãŒã«ãäœæããã«ã¯ããã©ã³ãµãŒã®[ã¢ããªã±ãŒã·ã§ã³ã«ãŒã«]ã¿ãã«ç§»åããŸãã
- ååãã«ãŒã«ã䜿çšããã¹ã¯ãªãããéžæãã[ä¿æ]ãã¯ãªãã¯ããŸãã
- ã«ãŒã«ãäœæãããããã§ã«æ§æãããŠããä»®æ³ãµãŒããŒãç·šéããå¿
èŠããããŸãã
- [詳现èšå®]ã¿ãã§ãäœæããã«ãŒã«ãè¿œå ããŸãã
äžèšã®äŸã§ã¯ãtlsv1ãµããŒããå«ãŸããŠããŸãã
ããã«ããã€ãã®äŸïŒ
ãã©ãã£ãã¯ãå¥ã®ããŒã«ã«ãªãã€ã¬ã¯ãããŸãã
ãã®ã¹ã¯ãªããã䜿çšãããšãã¡ã€ã³ããŒã«ãæ©èœããªãå Žåã«ãã©ãã£ãã¯ãå¥ã®ãã©ã³ã¹ããŒã«ã«ãªãã€ã¬ã¯ãã§ããŸãã ã«ãŒã«ãæ©èœãããã«ã¯ããã©ã³ãµãŒã§ããã€ãã®ããŒã«ãæ§æããã¡ã€ã³ããŒã«ã®ãã¹ãŠã®ã¡ã³ããŒãããŠã³ç¶æ ã«ããå¿ èŠããããŸãã IDã§ã¯ãªããããŒã«ã®ååãæå®ããŸãã
acl pool_down nbsrv(PRIMARY_POOL_NAME) eq 0 use_backend SECONDARY_POOL_NAME if PRIMARY_POOL_NAME
ãã©ãã£ãã¯ãå€éšãªãœãŒã¹ã«ãªãã€ã¬ã¯ãããŸãã
ã¡ã€ã³ããŒã«ã®ãã¹ãŠã®ã¡ã³ããŒãããŠã³ç¶æ ã®å Žåãããã§ãã©ãã£ãã¯ãå€éšWebãµã€ãã«ãªãã€ã¬ã¯ãããŸãã
acl pool_down nbsrv(NAME_OF_POOL) eq 0 redirect location http://www.example.com if pool_down
ãã®ä»ã®äŸã¯ãã¡ã ã
ããã¯ãã©ã³ãµãŒã«ã€ããŠã®ãã¹ãŠã§ãã 質åãããã°ãå°ããŠãã ãããç§ã¯çããæºåãã§ããŠããŸãã