RadWare AppDirector CLI配置_第1页
RadWare AppDirector CLI配置_第2页
RadWare AppDirector CLI配置_第3页
RadWare AppDirector CLI配置_第4页
RadWare AppDirector CLI配置_第5页
已阅读5页,还剩10页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

Radware AppDirector CLI 命令行配置手册命令行配置手册 Radware China 2007 3 19 刘庆明刘庆明 Ver1 0 本文是 Radware AppDirector 的快速配置手册 不包括 Radware CLI 的所有详细 说明 旨在为用户提供一个快速的配置介绍 本文档基于 AppDirector AS2 1 01 03 本文档是根据配置的顺序来组织的 请用户按照文档的顺序来配置 AppDirector 一般情况下 配置按照网络分层协议由低到高来进行 即先进行物理层和数据链路层 的配置 然后是网络层的配置 最后才是 4 7 层负载均衡的配置 如果未标明是主用设备还是备用设备 则主备配置是相同的 主备设备都需要配 置 首先通过 Console 口进行初始化配置 配置好必要的管理 IP 然后通过 Telnet 登 录 AppDirector 以下所有的命令均通过 Telnet 或 SSH 操作 Console 口主要用来观 察输出和排错 千万不要用来粘贴命令 切记 1 1基本配置基本配置 系统默认使用英文的制表符 会与中文系统的内码冲突 所以最好先关闭制表符的输 出 AppDirector OA net ip Interface Table 哪哪哪哪哪哪哪哪哪穆哪哪哪哪哪哪哪哪哪穆哪哪哪哪哪哪哪哪哪穆哪哪哪哪哪哪哪 哪哪 IP Address 砃 etwork Mask 矷 f Number 砎 lanTag 哪哪哪哪哪哪哪哪哪呐哪哪哪哪哪哪哪哪哪呐哪哪哪哪哪哪哪哪哪呐哪哪哪哪哪哪哪 哪哪 2 2 2 1 55 255 255 0 哪哪哪哪哪哪哪哪哪呐哪哪哪哪哪哪哪哪哪呐哪哪哪哪哪哪哪哪哪呐哪哪哪哪哪哪哪 哪哪 3 3 3 1 55 255 255 0 哪哪哪哪哪哪哪哪哪牧哪哪哪哪哪哪哪哪哪牧哪哪哪哪哪哪哪哪哪牧哪哪哪哪哪哪哪 哪哪 AppDirector OA manage terminal grid mode set dis Display of ascii graphics characters disabled AppDirector OA net ip Interface Table IP Address Network Mask If Number VlanTag 2 2 2 1 255 255 255 0 2 0 3 3 3 1 255 255 255 0 3 0 1 1 设备设备 以下两条命令是用来标识 AppDirector 设备的 给它们取个好记的名字 设置命 令提示符 让你知道现在正登录在哪台设备上 当设备多的时候 尤其是多设备冗余 时 主设备 system mib2 name set AD Master manage terminal prompt set AD Master 备设备 system mib2 name set AD Backup manage terminal prompt set AD Backup 1 2 管理管理 打开管理方式 telnet ssh http https 1 表示 enable 相应地 关闭它们是 set 2 manage telnet status set 1 manage ssh status set 1 manage web status 1 manage secure web status 1 1 3 全局表项全局表项 以下这些命令 任意一条更改后都需要重启机器才能生效 放在前面一次配置完 可以减少重启机器的次数 以下是二 三层转发表的配置 最好三条同时配置 这些值的大小直接会影响到 PPS 的性能 太小不利于大量 PPS 转发 太大会占用内存空间 system tune ip fft table set 256000 system tune arp table set 10000 会话表也是非常重要的配置 默认 16384 通常都不够 ASI 建议设置为 200000 以内 AS2 AS4 设置为 400000 以内 system tune client table set 300000 system tune request table set 2000 如果需要 Client NAT 一定需要将此表调大 该值默认为 0 而且大小最好按实际 需要定义 因为此表非常占用内存空间 数值表示 NAT 地址数目 system tune nat address table set 2 2 2网络配置网络配置 2 1 物理端口物理端口 建议通常情况下将物理电接口地址都设置为 非协商 全双工 并设定速率 net physical interface set 1 s Fast Ethernet d Full net physical interface set 17 s Giga Ethernet d Full 2 2 Interface 格式如下 net ip interface create IP 地址地址 子网掩码子网掩码 接口号接口号 主用负载均衡设备 net ip interface create 192 168 255 47 255 255 255 192 1 上面的例子在和 FE 1 上创建了 IP 地址 备用设备 net ip interface create 192 168 255 48 255 255 255 192 1 2 3 路由和默认网关路由和默认网关 net route table create 0 0 0 0 0 0 0 0 192 168 255 1 i 1 目标网段和掩码后面紧跟的是下一跳接口地址 i 表示该路由的下一跳的接口号 例子中第一条是默认网关的配置 2 4 Virtual IP Interface Radware Virtual IP Interface 服务有两个作用 1 为用户提供 DNS 服务 主要是 GSLB 使用 2 为 Redundancy 提供一个浮动 IP 地址 这个 IP 地址通常做为服务器的网关 在冗余切换后 该地址能够被服务器 Ping 通 主机配置 appdirector l4 policy table create 192 168 255 49 Any Any 0 0 0 0 Float IP ta Virtual IP Interface 备机配置 appdirector l4 policy table create 192 168 255 49 Any Any 0 0 0 0 Float IP ta Virtual IP Interface rs Backup 3 3负载均衡配置负载均衡配置 3 1 Farm 配置配置 以下是 Farm table 的命令说明 虽然很复杂 但用到的命令不多 加粗部分是例 子中用到的 基本足够 AppDirector 的 Farm 配置中 已经不需要 IP 地址了 VIP 配置在 L4 Policy 中 appdirector farm table help set destroy del create add help Switches as Admin Status at Aging Time sec dm Dispatch Method cm Connectivity Check Method cp Connectivity Check Port ci Connectivity Check Interval sec cr Connectivity Check Retries ct Capacity Threshold rm Redirection Mode ef Extended Check Frequency hp Home Page sm Sessions Mode df DNS Redirection Fallback hm HTTP Redirection Mode bl Bandwidth Limit un Authorized Username pw Authorized Password appdirector farm table create VSDP as Enabled dm Cyclic cm TCP Port cp 80 sm EntryPerSession appdirector farm table create IVRP as Enabled dm Cyclic cm TCP Port cp 80 sm EntryPerSession appdirector farm table create RBT as Enabled dm Cyclic cm TCP Port cp 80 sm EntryPerSession 3 2 NAT 配置配置 appdirector nat client status set enable 全局打开 Client NAT appdirector nat client range to nat create 192 168 255 1 t 192 168 255 63 定义需要实施 Client NAT 的用户地址范围 这里是本网段 外网用户不需要做 NAT 主设备主设备 appdirector nat client address range create 192 168 255 50 t 192 168 255 50 定义 NAT 需要使用的地址 这个地址的数目不能大于在全局 NAT 表中的条目 2 备设备 appdirector nat client address range create 192 168 255 51 t 192 168 255 51 address range 配置与 address range 是相关联的 在 Farm 配置中 只需要 配置 address range 地址 range to nat 是不可见的 3 3 使用了使用了 Client NAT 后的后的 Farm 附加配置附加配置 指定某个 Farm 需要做 Client NAT 并指明使用哪个 NAT 地址来做地址翻译 如果不需要 Client NAT 此项不必配置 主设备主设备 appdirector farm extended params set VSDP nr 192 168 255 50 appdirector farm extended params set IVR nr 192 168 255 50 appdirector farm extended params set RBT nr 192 168 255 50 备设备 appdirector farm extended params set VSDP nr 192 168 255 51 appdirector farm extended params set IVR nr 192 168 255 51 appdirector farm extended params set RBT nr 192 168 255 51 3 4 服务器配置服务器配置 appdirector farm server table AppDirector OA appdirector farm server table help appdirector farm server table help set destroy del create add help Switches sn Server Name w Weight om Operation Mode st Type cl Connection Limit as Admin Status bl Bandwidth Limit rt Redirect To cn Client NAT sd Server Description rs Response Threshold ms ba Backup Server Address pm Backup Preemption nr Client NAT Address Range 在 Radware AppDirector 配置中 服务器是与 Farm 绑定在一起的 在 WEB 与 CLI 中 不能单独定义一个没有 Farm 的 Server 同一个 Server 在不同的 Farm 中 可以使用相同的 Server Name appdirector farm server table create VSDP 192 168 255 7 0 sn vsdp 1 cn Enabled appdirector farm server table create VSDP 192 168 255 8 0 sn vsdp 2 cn Enabled appdirector farm server table create IVR 192 168 255 13 0 sn ivr 1 cn Enabled appdirector farm server table create IVR 192 168 255 14 0 sn ivr 2 cn Enabled appdirector farm server table create RBT 192 168 255 41 0 sn rbt 1 cn Enabled appdirector farm server table create RBT 192 168 255 42 0 sn rbt 2 cn Enabled 3 5 L4 Policy 以前的以前的 SuperFarm 配置配置 Farm 需要通过 VIP 对外提供服务 并且根据服务端口来区分 Farm 必须配置 L4 Policy 此例中只介绍了 L4 的 L4 Policy AppDirector OA appdirector l4 policy table help appdirector l4 policy table help set destroy del create add help Switches ipt Source IP To po L7 Policy fn Farm Name ta Application bp Backend Encryption Port dr Bytes of Request to Read rs Redundancy Status pc POST Classification Input nr HTTP Normalization pm L7 Persistent Switching Mode sn Segment Name efn Explicit Farm Name 主设备主设备 appdirector l4 policy table create 192 168 255 52 TCP 80 0 0 0 0 P VSDP fn VSDP appdirector l4 policy table create 192 168 255 53 TCP 80 0 0 0 0 P IVR fn IVR appdirector l4 policy table create 192 168 255 54 TCP 80 0 0 0 0 P RBT fn RBT 备设备备设备 appdirector l4 policy table create 192 168 255 52 TCP 80 0 0 0 0 P VSDP fn VSDP rs Backup appdirector l4 policy table create 192 168 255 53 TCP 80 0 0 0 0 P IVR fn IVR rs Backup appdirector l4 policy table create 192 168 255 54 TCP 80 0 0 0 0 P RBT fn RBT rs Backup 做冗余时 备机上记得将加上 rs Backup 如第二条的配置 系统默认是主用模 式 4 4VRRPVRRP 配置 双机备份时需要配置 配置 双机备份时需要配置 4 1 Vrrp 全局配置全局配置 redundancy mode set VRRP redundancy interface group set enable 主机上使用 备机不用 redundancy backup fake arp set disable redundancy backup in vlan set disable 4 2 VR 配置配置 主设备主设备 redundancy vrrp virtual routers create 1 10 as down p 200 备设备备设备 redundancy vrrp virtual routers create 1 10 as down p 100 4 3 Associated IP 配置配置 WSD OA redundancy vrrp associated ip help redundancy vrrp associated ip help set destroy del create add help redundancy vrrp associated ip create 1 10 192 168 255 49 redundancy vrrp associated ip create 1 10 192 168 255 52 redundancy vrrp associated ip create 1 10 192 168 255 53 redundancy vrrp associated ip create 1 10 192 168 255 54 5 5常用管理命令常用管理命令 注 如果注 如果 Console 显示中存在乱码 请输入如下命令 显示中存在乱码 请输入如下命令 manage terminal grid mode set disable 5 1 manage terminal traps output AppDirector OA manage terminal traps output set 2 打开屏幕信息输出功能 这样所有的设备输出信息都不会屏蔽 AppDirector OA manage terminal traps output set 3 关闭屏幕信息输出功能 这样所有的设备输出 包括出错 信息屏蔽 5 2 net ip appdirector net ip Interface Table IP Address Network Mask If Number VlanTag 10 160 4 21 255 255 255 0 100002 0 10 161 240 1 255 255 255 0 100003 0 192 168 1 15 255 255 255 0 16 0 显示接口地址的配置 也可以做相应修改 net ip interface net ip interface help get set destroy del create add help Switches i If Number m Network Mask f Fwd Broadcast ba Broadcast Addr v VlanTag Displays the IP Interfaces Table 例如 如果要将 192 168 1 15 接口址改为端口 F 15 net ip set 192 168 1 15 i 15 注 如果要将 192 168 1 15 改为 192 168 1 16 则只能先删除再增加新的地址 5 3 appdirector farm table appdirector appdirector farm table Farm Table Farm Name Admin Status Aging Time Dispatch Connectivity sec Method Check Method www Enabled 60 Cyclic TCP Port UDP test Enabled 60 Cyclic UDP Port test Enabled 60 Cyclic HTTP Page 这条命令显示了所有的 Farm 配置情况 5 4 appdirector farm server table appdirector appdirector farm server table Server Table Farm Address Server Address Server Name Operational Attached Users Status 10 160 4 20 10 161 240 2 GuangTieOA 1 Not In Service 0 10 160 4 20 10 161 240 3 GuangTieOA 2 Not In Service 0 10 160 4 20 10 161 240 4 GuangTieOA 3 Not In Service 0 10 160 4 20 10 161 240 5 GuangTieOA 4 Active 0 这个显示了所有服务器的工作状态和连接的用户数 5 5 sys config immediate AppDirector OA sys config immediate Device Configuration Date 18 10 2006 07 23 06 DeviceDescription AppDirector with Cookie Persistency BWM IPS and DoS an d B DoS Base MAC Address 00 03 b2 26 64 00 Software Version 1 01 03 build 8e67f4 net vlan table create 100002 p ip t switch net vlan table create 100003 p ip net ip interface create 2 2 2 1 255 255 255 0 2 net ip interface create 3 3 3 1 255 255 255 0 3 net ip interface create 192 168 1 1 255 255 255 0 16 net route table create 0 0 0 0

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

最新文档

评论

0/150

提交评论