Symmetric Load Balancing

Symmetric load balancing is a mechanism of interchanging the source and destination addresses to ensure that bidirectional traffic specific to a particular source and destination address pair flows out of the same member of a trunk group. Symmetric load balancing of non-IP data traffic is not supported.
Note: Symmetric load balancing is supported on RUCKUS ICX 7550 and RUCKUS ICX 7850.

For many monitoring and security applications, bidirectional conversations flowing through the system must be carried on the same port of a LAG. For network telemetry applications, network traffic is tapped and sent to a RUCKUS ICX device, which can send hash-selected traffic to the application servers downstream. Each server analyzes the bidirectional conversations. Therefore, the devices must enable symmetric load balancing to accomplish bidirectional conversations. In addition, the firewall between the RUCKUS ICX devices can be configured to allow the bidirectional conversations per link of the LAG. These network telemetry applications also require symmetric load balancing on the LAGs between the devices.

Note: Symmetric load balancing can also be used in case of Equal-cost multi-path routing (ECMP) where the same next hop is selected for bidirectional conversation.

You can enable symmetric load balancing for IPv4 and IPv6 data traffic on RUCKUS ICX devices using the load-balance symmetric command in global configuration mode.

To confirm whether symmetric load balancing is enabled, use the show running-config command. If "symmetric-hash" is displayed in the LAG portion of the output, then symmetric load balancing is enabled for the LAG.

Note: Symmetric load balancing is a system-level configuration and may affect load sharing among LAG members as compared to non-symmetric load balancing and the ECMP next-hop load sharing by not fairly utilizing all the LAG links. It might also affect load sharing within a stack trunk in case of broadcast, unknown unicast, and multicast (BUM) traffic where you may not see all the stack trunk member links getting fairly utilized.

Fields Used for Hash Calculation Based on Packet Types

Packet Type Hashing Field Is Symmetric Load Balancing Supported on RUCKUS ICX Platforms?
Non-IP packets Source MAC address and destination MAC address No
IPv4/IPv6 packets SIP, DIP, protocol type, and Layer 4 source or destination ports (only if non-fragmented packet) Yes
TCP/UDP packets SIP, DIP, protocol type, and Layer 4 source or destination ports (only if non-fragmented packet) Yes
IP-in-IP tunnel/GRE packets Layer 4 source or destination ports (only if non-fragmented packet), SIP, DIP, and protocol type from the inner IP payload Yes

Use Case: Deploying RUCKUS ICX 7850 as a Traffic Splitter in a DPI Solution

Symmetric Load Balancing in RUCKUS ICX 7850

Production network: Traffic flowing in the production network is mirrored onto a few ports that connect to the monitoring network.

Monitoring network: In the monitoring network, the RUCKUS ICX 7850 is deployed as a traffic splitter. There are multiple servers hosting the DPI application and connected to RUCKUS ICX 7850. All monitored traffic is transparently flooded onto the VLAN and is load-balanced among the outgoing ports connected to the DPI pool.

Note: This use case assumes that traffic going both ways between the same IP addresses and ports is always sent to the same DPI device connected to a LAG port.

After enabling symmetric load balancing, the mirrored upstream traffic and mirrored downstream traffic will hash to the same LAG member link, ensuring that the full bidirectional flow is sent to the same DPI pool.