Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 18: Load Balancing

18.9 Gateway Load Balancer

Why appliances are not Nginx

A firewall, an intrusion-detection box, or a similar appliance must see the traffic and then send it onward. It is not a website with a Host header. You do not put it in site-a-tg. A Gateway Load Balancer exists to scale those appliances and to send packets through them.

What it is

The targets speak GENEVE on port 6081, not HTTP. You place a Gateway Load Balancer endpoint in the application subnet. The subnet route table sends traffic to that endpoint instead of straight to the internet gateway. The appliance inspects the packets and returns them. The original source and destination stay intact. This course does not build a firewall image. The route is the lesson.

How the path is wired

  1. Draw the application subnet and a separate appliance subnet.
  2. Create a target group with protocol GENEVE and port 6081.
  3. Register the appliance instances in that group.
  4. Create a Gateway Load Balancer in the appliance subnets and attach that target group.
  5. Create a Gateway Load Balancer endpoint in the application subnet.
  6. Edit the application route table so the default route points at that endpoint.
  7. You should see packets arrive at the appliance and leave again toward the original destination.
  8. Do not create this balancer in the lab unless you already have an appliance image to register. The drawing is the required result.