Solved

WINDOWS 2003 NLB \ WINDOWS FIREWALL

Posted on 2010-09-09
8
621 Views
Last Modified: 2012-05-10
I have two 2003  web servers and would like to use them with NLB. Is it possible to use NLB and use the windows firewall as well?
0
Comment
Question by:webiis
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
8 Comments
 
LVL 3

Accepted Solution

by:
rob_AXSNL earned 500 total points
ID: 33640303
No you can't as the whole NLB network must be protected as someone could mess up the heart beat. So, the NLB subnet must be protected by a firewall.
0
 

Author Comment

by:webiis
ID: 33640560
Ah! so the NLB cluster IP can not be a public IP. Must be a private IP with a nat setup.
0
 
LVL 13

Expert Comment

by:Greg Hejl
ID: 33641270
you can run the heartbeat on a backend subnet or on a management lan.

NLB can have a public address - MS firewall would need to be carefully setup. members of the nlb operate their own firewalls.

but - any new build should be placed behind a nat firewall. best practice
0
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

 

Author Comment

by:webiis
ID: 33641403
I can setup a backend subnet pretty easily. I am running v sphere. I'm not sure what you mean by "members of nlb operate their own firewalls" ?
Do I enable the windows firewall on each server? Will it block functions of NLB?
0
 
LVL 13

Expert Comment

by:Greg Hejl
ID: 33642829
set up nlb - look over your domain fw settings for nlb entries - apply public fw to adapter - test nlb

if you put behind NAT fw then you wont have to worry about it.
0
 
LVL 3

Expert Comment

by:rob_AXSNL
ID: 33644315
Ah! so the NLB cluster IP can not be a public IP. Must be a private IP with a nat setup.

Behind a firewall doesnt mean is has to be nat. You can assign a public ip address to your dmz and just open up tcp 80 and 443...
0
 

Author Comment

by:webiis
ID: 33652297
greg - do you have an article you can forward me on the setup using the native windows firewall. Just so I have some kind of guide.
0
 
LVL 13

Expert Comment

by:Greg Hejl
ID: 33652670
sure thing:

http://technet.microsoft.com/en-us/network/bb545423.aspx

http://blogs.technet.com/b/mempson/archive/2008/02/26/key-firewall-ports-for-windows-server-2008.aspx

this shows both UI's for the firewall:
http://blogs.technet.com/b/sbs/archive/2010/02/18/managing-your-firewalls-with-sbs-2008-and-windows-7.aspx

this talks about replication port usage:  there's a good link to IANA port numbers in it.

http://blogs.technet.com/b/askds/archive/2007/08/24/dynamic-client-ports-in-windows-server-2008-and-windows-vista-or-how-i-learned-to-stop-worrying-and-love-the-iana.aspx

the rules in the firewall are very granular and will allow you to open ports just for your subnets and/or public access.

I do not recommend placing the server directly on the internet.  
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question