System Configuration

Local Configuration

System date & time

The system date and time can be configured automatically using NTP or set manually.

To configure NTP:

  1. Using the WebUI, navigate to Local Configuration > System date & time.

    system date time
  2. Select Use NTP servers.

  3. Select the required System timezone settings.

  4. Specify the NTP servers. Both IP addresses and FQDNs can be used.

  5. Click Submit.

To manually specify the date and time:

  1. Select Set date and time manually.

  2. Select the required System timezone settings.

  3. Configure the Date and Time.

  4. Click Submit.

User interface

To configure user interface settings:

  1. Using the WebUI, navigate to Local Configuration > User Interface.

    user interface settings
  2. Select the required IP address. The drop-down is populated with static IPs.

  3. Set the required API/WebUI Port.

  4. Select the required SSL Certificate.

  5. If SSH access is required, check the SSH enabled checkbox and specify the SSH port.

Physical - advanced configuration

Hostname & domain

To configure the hostname and domain:

  1. Using the WebUI, navigate to Local Configuration > Physical - advanced configuration.

    configure hostname domain
  2. Specify the Hostname and Domain.

  3. Click Submit.

Internet access (HTTP proxy)

To configure a proxy server to use for Internet access:

  1. Using the WebUI, navigate to Local Configuration > Physical - advanced configuration.

  2. Scroll to the Internet access (HTTP proxy) section.

    configure proxy
  3. Enable (check) the Enabled checkbox.

  4. Specifiy the Address of the proxy server. An IP address or FQDN can be used.

  5. Specify the Port of the proxy server.

  6. If authentication is used, specify the Username or email address and the Password.

  7. Click Submit.

Console

To enable console & SSH access:

  1. Using the WebUI, navigate to Local Configuration > Physical - advanced configuration.

  2. Scroll to the Console section.

    configure console
  3. Enable (check) the Enabled checkbox.

  4. Specifiy a Password for the "loadbalancer" user.

  5. Click Submit.

Firewall

To set the firewall connection tracking table size:

  1. Using the WebUI, navigate to Local Configuration > Physical - advanced configuration.

  2. Scroll to the Firewall section.

    configure firewall
  3. Specify the Connection tracking table size.

  4. Click Submit.

Keyboard

  1. Using the WebUI, navigate to Local Configuration > Physical - advanced configuration.

  2. Scroll to the Keyboard section.

    configure keyboard
  3. Select the required Keymap.

  4. Click Submit.

SMTP relay

To configure an SMTP relay server:

  1. Using the WebUI, navigate to Local Configuration > Physical - advanced configuration.

  2. Scroll to the SMTP Relay section.

    configure smtp relay
  3. Enable (check) the Enabled checkbox.

  4. Specifiy the SMTP server address of the relay server. An IP address or FQDN can be used.

  5. Specify the SMTP port of the relay server.

  6. If authentication is used, specify the SMTP username or email address and the SMTP Password.

  7. Click Submit.

SNMP Configuration

A [Service IP] must be available first before configuring SNMP.
  1. Using the WebUI, navigate to Local Configuration > SNMP configuration.

  2. Click Add SNMP Settings.

    configure snmp
  3. Select the relevant SNMP version number(s).

  4. Specify the Community string (SNMP V2 only), Location and Contact.

  5. Select the Service IP from the dropdown and specify the required Port.

  6. Click Submit.

Installing the License Key

The appliance can be used completely unrestricted for 30 days without installing a license key. After 30 days, the appliance continues to work but it’s no longer possible to make configuration changes.

if you’re conducting a PoC (Proof of Concept) using the VA and require more time to complete your evaluation, please contact sales@loadbalancer.org who will be able to provide guidance on how to extend the trial.

For an unlicensed VA, the following message is displayed:

30day msg va

For an unlicensed hardware appliance, the following message is displayed:

30day msg hw

To apply the license key:

  1. Using the WebUI, navigate to: Local Configuration > License Key.

    install licence key
  2. Enter the licence key as shown above.

  3. Click Submit.

Format is : @license key@

Once the license is applied, these warning messages will no longer be displayed.

Execute shell command

  1. Using the WebUI, navigate to Local Configuration > Execute shell command.

    execute shell command
  2. Either select a Common Command from the dropdown or enter your own using the Command input field.

  3. Click Submit to run the command. Command output will be displayed in the area below the Command input field.

Collectors

Prometheus

The Prometheus collector can provide both Layer 7 (HAProxy) and local node metrics.

To enable the Prometheus Collector:

A [Service IP] must be available first before configuring Prometheus.
  1. Using the WebUI, navigate to Local Configuration > Collectors > Prometheus.

    configure prometheus
  2. Enable (check) the Enabled Layer 7 Exporter checkbox to provide Layer 7 metrics.

  3. Update the Exporter port if required.

  4. Enable (check) the Enabled Node Exporter checkbox to provide local node metrics.

  5. Update the Exporter port if required.

  6. Select the required Service IP.

  7. Click Submit.

Portal management - NOTE - currently disabled in teh ISO image

The Loadbalancer.org ADC Portal is an ultra-secure, cloud-based ADC management platform that enables ADCs from Loadbalancer.org and multiple other vendors including F5, Citrix Netscaler and Progress Kemp to be monitored and managed. This enables centrally controlled backups, software updates, real-time security alerts (CVEs) and secure remote access for all connected ADCs. To add an appliance to the Portal, follow the steps below.

Step 1 - Configure Portal Connection Details

Step 2 - Start the Appliance Adoption Process

Step 3 - Adopt the Shuttle

Step 4 - Add the ADC to the Portal

  1. Click LOADBALANCER | PORTAL in the Portal’s main menu bar to view the Dashboard.

  2. In the ADCs panel:

    • If there are currently no ADCs, click Connect an ADC.

      • In the menu to the left, select List.

    • if ADCs have already been added, click View my ADCs.

  3. Click the Add ADC button.

    add adc from portal1
  4. Click the Add button for Loadbalancer Endurance.

    add adc from portal3 endurance
  5. Specify the Username/Email and Password for a valid Endurance user.

  6. Select the required Namespace.

  7. Enter the IP address of the appliance being added.

  8. Leave the Port set to the default value (443) unless this has been changed for the appliance being added.

  9. Click Next.

    add adc from portal4 endurance
  10. Enter an appropriate Label (name) for the appliance.

  11. Ensure that the IP Address is correct.

  12. Leave the Port set to the default value (443) unless this has been changed for the appliance being added.

  13. Click Next.

  14. Enter any required Notes and Tags to describe the appliance and click Next.

    To create a tag, enter the required name and hit Enter. The tag will appear colored blue under the Tags field. Repeat to specify multiple tags (up to 30).
  15. Verify all settings, these can be changed if needed using the relevant Edit option.

  16. Click Submit - if the details have been specified correctly, the appliance will appear in the list.

The Portal connection method above uses a Shuttle and connection for each ADC. It’s also possible to configure a single dedicated Shuttle and use this for all ADCs. For more information, see the Portal Guide.

Network Configuration

Interfaces

The appliance ships with 4 interfaces, each interface can be used for any purpose. IP Groups (Subnets) are created and associated with an interface, Static IPs and Floating IPs can then be created within each subnet. Multiple interfaces can be bonded if required, VLANs can be configured for an interface or bond. This architecture allows subnets/IP addresses to be easily moved between interfaces.

To view all interfaces:

  1. Using the WebUI, navigate to Network > Interfaces.

    view interfaces

To view/edit an interface:

  1. Click the three dots menu next to the Interface you’d like to view or edit.

    edit interface
  2. Update the Name if required.

  3. Update the MTU if required.

  4. Enable (check) the Onboot checkbox to enable the interface on boot up.

  5. Enable (check) the Offload checkbox to enable hardware NIC offloading (where available).

  6. Configure the required Domain name servers for the interface.

  7. Click Submit to save any changes.

Bonding

To Configure bonding:

  1. Using the WebUI, navigate to Network > Interfaces.

    view interfaces
  2. Click Add Bond.

    edit bonding
  3. Specify a Name for the bond.

  4. Select the interaces to be bonded.

  5. Select the bonding Mode, the options are:

    • Balance-rr - balance round robin. Transmits packets in a numerical order from the first available Secondary through to the last.

    • active-backup - This places one of the adapters in a backup state and will only become active if the link is lost to the active adapter. This mode provides fault tolerance.

    • 802.3ad - Dynamic link aggregation mode. This mode requires a switch that supports IEEE 802.3ad.

  6. Update the MTU if required.

  7. Configure the required Domain name servers for the bond.

  8. Click Submit.

For multiple nodes in HA mode, configure bonding in the same way on each node.

VLANs

To add a VLAN:

  1. Using the WebUI, navigate to Network > Interfaces.

    view interfaces

To view/edit an interface:

  1. Click the three dots menu next to the Interface you’d like to view or edit.

    edit interface
  2. Update the Name if required.

  3. Update the MTU if required.

  4. Enable (check) the Onboot checkbox to enable the interface on boot up.

  5. Enable (check) the Offload checkbox to enable hardware NIC offloading (where available).

  6. Configure the required Domain name servers for the interface.

  7. Click Submit to save any changes.

Mode 0 - Balance round robin. Transmits packets in a numerical order from the first available Secondary through to the last. Mode 1 - Active Backup (default). This places one of the adapters in a backup state and will only become active if the link is lost to the active adapter. This mode provides fault tolerance. Mode 4 - 802.3ad. Dynamic link aggregation mode. This mode requires a switch that supports IEEE 802.3ad.

In access mode switch ports are dedicated to one VLAN. The switch handles all the tagging and de-tagging of frames - the station connected to the port does not need to be configured for the VLAN at all. In trunk mode the switch passes on the raw VLAN frames - the station connected must be configured to handle them. Trunk mode is usually used to connect two VLAN-carrying switches, or to connect a server or router to a switch.

If the load balancer is connected to an access mode switch port, no VLAN configuration is required. If the load balancer is connected to a trunk port, then all the required VLANs must be configured on the load balancer.

To configure a VLAN:

For multiple nodes in HA mode, configure VLANs in the same way on each node.

IP Groups (Subnets)

  1. Using the WebUI, navigate to Network > Static IPs and click Add IP Group.

    configure ipgroup
  2. Specify a relevant Name, e.g. Backend Servers.

  3. Specify the Network Address, e.g. 192.168.100.0.

  4. Specify the Mask, e.g. 28.

  5. Select the Interface to use for this IP group.

  6. Specify the Gateway, e.g. 192.168.100.14.

  7. Click Add.

CIDR notation is used to specify the mask. For information on CIDR notation, see Appliance IPv4 Address Format (CIDR notation).

Static IPs

Static IPs are used for:

  • The WebUI / API / SSH

  • Pulse (HA)

To add a Static IP:

  1. Using the WebUI, navigate to Network > Static IP and click Add static IP.

    configure static ip
  2. Select the relevant IP Group (subnet) where the IP should be created.

  3. The network portion of the address with be auto filled, complete the remainder of the address.

  4. Click Add.

Floating IPs

Floating IPs are used for Virtual Services. This allows the Virtual Service to move or "float" between nodes.

They are also required when using layer 4 DNAT mode or Layer 7 proxy mode with TProxy where in both cases the load balancer must be the default gateway for the Real Servers. Again, this allows the Virtual gateway to move or "float" between nodes.

Floating IPs are controlled by Pulse to ensure that only the active node owns the Floating IP(s) at any time.

To add a floating IP:

  1. Using the WebUI, navigate to Network > Floating IPs and click Add Floating IP.

    configure floating ip
  2. Select the relevant IP Group (subnet) where the IP should be created.

  3. The network portion of the address with be auto filled, complete the remainder of the address.

  4. By default the address will be enabled once created. If this is not desired, disable (clear) the Enable floating IP checkbox.

  5. Click Add.

Firewall Marks

Firewall marks are used to group ports and protocols into a single Virtual Service. For example, firewall marks can be used to bundle HTTP connections on port 80 and secure HTTPS connections on port 443 for an e-commerce site. By assigning the same firewall mark to each protocol, state information for the transaction can be preserved because the load balancer forwards all requests from a particular client to the same Real Server.

Regions

Routing

Static Routes

Local Routes

Policy Based Routing (PBR)

If you require a custom gateway for a particular Service, this can be achieved using PBR.

If client source addresses are known and predictable, static routes should normally be used to route traffic. In other situations where this is not known or the network is large with many subnets, PBR can be used. Here, return traffic is routed based on the source address of the reply traffic (the VIP/floating IP) rather than on the destination address (the client’s IP).

To configure a VIP to return traffic via a custom gateway rather than via the default gateway:

Service IPs

Service IPs are used for:

  • SNMP

  • Prometheus collector