Avaya Secure Remote Access Uživatelský manuál Strana 18

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 33
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 17
Secure Remote Access Technical Solution Guide v1.0
______________________________________________________________________________________________________
18
4.2.1.5 VPN Gateway clustering
The Nortel VPN Gateway provides built-in support for clustering multiple Gateways. Up to 255
devices can participate in a cluster. The benefits of clustering include:
Higher availability (active/active resiliency)
Higher scale (higher throughput, more concurrent user sessions)
Single system management (a cluster of Gateways is managed as a single system in
terms of configuration and software management)
No requirement for load-balancing switches
Each Gateway in a cluster hosts a unique VIP address for each VPN domain configured. You can
use round robin DNS to distribute clients across the cluster members. If a cluster member fails,
the VIP addresses associated with the failed unit are migrated to a healthy unit and continue to
operate. This provides a simple and effective way to scale the solution and avoids typical issues
with round robin DNS strategies, such as directing users to failed gateways, as all DNS entries
resolve to an in-service gateway unless all gateways are unavailable.
4.2.1.6 Application Switch load-balancing
For higher-scale resiliency, you can integrate the VPN Gateway with the Nortel Application Switch
portfolio to actively load-balance requests. This provides a solution with a single VIP per VPN
domain, intelligent user load-balancing, and advanced service health-checking to direct traffic to
available gateways.
Figure 3 on page 19 depicts such an active/active high-availability (HA) topology utilizing dual
Nortel Application Switch 3408 switches to provide a highly scalable solution with no single point
of failure. Such a solution can easily scale to 50,000 or more active users. Note that all VPN
Gateways are active and use backup network connections to the non-primary Application Switch.
These connections are not shown in the diagram but ensure that even in the case of a switch
failure, all VPN Gateways have network connectivity and remain operational.
Zobrazit stránku 17
1 2 ... 13 14 15 16 17 18 19 20 21 22 23 ... 32 33

Komentáře k této Příručce

Žádné komentáře