Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Interesting Web Farm Load Balancing Facts that You Didn't Know Before

Interesting Web Farm Load Balancing Facts that You Didn’t Know Before

Consider the following fun facts regarding Web Farm Load Balancing with ISA 2006 Firewalls:

  • Load balancing is not supported for Secure Sockets Layer (SSL) connections tunneled through the ISA Firewall (which is server publishing, not Web publishing). It is only supported in Web publishing, when the HTTPS connection is terminated on at the ISA Firewall, and then forwarded over HTTP or HTTPS to the Web farm (which represents SSL to SSL bridging).
  • For SSL bridging scenarios, both IP affinity (source IP-based) and session affinity (cookie-based) are supported.
  • In an SSL to SSL bridging scenario, the servers in the Web farm authenticate to the ISA Firewall with a server certificate. You can deploy these certificates as follows:
    • Deploy a server certificate on each server in the Web farm. For example, if the server farm consists of Server1.internal.net, Server2.internal.net, and Server3.internal.net, you must acquire a unique certificate for each server, with the name of the farm member as it appears in the server farm object.
    • Alternatively, deploy a server certificate for the Web farm object. In this case, you acquire a certificate with the internal name you specified for the Web publishing rule for the farm, and deploy the certificate on each server in the Web farm. In this case, you use the same name for each server certificate installed on the Web farm members. The key is that name is used in the Web Publishing Rule.

For more information about Warm Farm Load Balancing, check out:

http://www.microsoft.com/technet/isa/2006/deployme...b.mspx

HTH,

Tom

Thomas W Shinder, M.D.
Site: http://www.isaserver.org/

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

One Response to “Interesting Web Farm Load Balancing Facts that You Didn’t Know Before”

  1. Adminaid.net » Blog Archive » Interesting Web Farm Load Balancing Facts that You Didn’t Know Before Says:

    January 12th, 2008 at 2:01 pm

    […] Consider the following fun facts regarding Web Farm Load Balancing with ISA 2006 Firewalls: Load balancing is not supported for Secure Sockets Layer (SSL) connections tunneled through the ISA Firewall (which is server publishing, not Web publishing). It is only supported in Web publishing, when the HTTPS connection is terminated on at the ISA Firewall, and then forwarded over HTTP or HTTPS to the Web farm (which represents SSL to SSL bridging). more… […]

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center