Symmetric Load Balancing
For many monitoring and security applications, bidirectional conversations flowing through the system must be carried on the same port of a LAG. For network telemetry applications, network traffic is tapped and sent to a RUCKUS ICX device, which can send hash-selected traffic to the application servers downstream. Each server analyzes the bidirectional conversations. Therefore, the devices must enable symmetric load balancing to accomplish bidirectional conversations. In addition, the firewall between the RUCKUS ICX devices can be configured to allow the bidirectional conversations per link of the LAG. These network telemetry applications also require symmetric load balancing on the LAGs between the devices.
You can enable symmetric load balancing
for IPv4 and IPv6 data traffic on RUCKUS ICX devices using the
load-balance
symmetric command in global configuration mode.
To confirm whether symmetric load
balancing is enabled, use the show running-config command. If "symmetric-hash" is displayed in the LAG
portion of the output, then symmetric load balancing is enabled for the LAG.
Fields Used for Hash Calculation Based on Packet Types
Use Case: Deploying RUCKUS ICX 7850 as a Traffic Splitter in a DPI Solution
Production network: Traffic flowing in the production network is mirrored onto a few ports that connect to the monitoring network.
Monitoring network: In the monitoring network, the RUCKUS ICX 7850 is deployed as a traffic splitter. There are multiple servers hosting the DPI application and connected to RUCKUS ICX 7850. All monitored traffic is transparently flooded onto the VLAN and is load-balanced among the outgoing ports connected to the DPI pool.
After enabling symmetric load balancing, the mirrored upstream traffic and mirrored downstream traffic will hash to the same LAG member link, ensuring that the full bidirectional flow is sent to the same DPI pool.
