Re: One arm vs. Two arm configuration

Kenneth Salchow <[email protected]>
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <4B18A8F75A6384449755BC7784073E935FF0044680@exch11.olympus.f5net.com>
That's an excellent question.  J The reason I say that is because you are
bound to get a lot of opinions on this one.  

 

Me, personally, I have always voted for the two-arm (or more precisely, an
interface per network as it can be more than just two).  I have two specific
reasons:

 

1.       Just from a straight-forward networking perspective, using a single
interface for inbound and outbound traffic, just cuts your top-end
throughput in half (at best and assuming bi-directional traffic flow through
the ADC) and can significantly make troubleshooting a big pain.

2.       From a security/segmentation standpoint, I like the fact that they
only way to get to my servers is through the ADC device-you can't circumvent
it in anyway.  So, you have much better control on the traffic coming and
going to the back-end servers.

 

However, a single arm configuration has a couple things going for it:

 

1.       If you are wanting to do a DSR configuration-it is infinitely
easier to load-balance inbound connections and then just 'get out of the
way' with a one-arm config-especially if you aren't in need of masking the
servers real IP.

2.       If you are trying to do asymmetric routing to enable internal
remote administration of devices that serve external content-not having to
configure the ADC to allow it can simplify the ADC configuration-so a
one-arm config is easier to do that with (which is really the same as
#1-i.e. you can more easily get the ADC 'out of the way' of the other things
you want to do.

 

I'm a big fan of control, security and auditing, so I naturally go for the
multi-arm configuration because I like having that segmentation.  I think it
improves overall performance of the design, simplifies troubleshooting and
gives you more flexibility for adapting to changing network needs down the
road (like, what if you suddenly need to support IPv6, but your servers
don't?  a two arm configuration makes it pretty darn easy to adjust for
this-although, it's not impossible with a one-arm).  I am NOT a big fan of
DSR.

 

I'm sure someone will have other comments-but I hope my little ole opinion
helped you some.

 

KJ (Ken) Salchow, Jr.  |  Manager, Technical Marketing

 

From: [email protected] [mailto:[email protected]] On Behalf Of
Bryan Call
Sent: Monday, March 30, 2009 11:41 AM
To: [email protected]
Subject: [load balancing] One arm vs. Two arm configuration

 

Most load balancing vendors support both a one armed and a two armed
configuration.  My question is what are the compelling reasons to go with
one over the other if you designing a network and don't have preexisting
conditions that force you one direction? 

 

Thanks,

 

Bryan Call - V.P. Of Technology

Burstabit Media, Inc.

3130 West Maple Loop, Suite G-75, Lehi, UT 84043

[P] 801-331-6945 Ext: 1103 [F] 801-880-8884
AIM: 

 <http://www.burstabit.com/> Glass-logo

THE INFORMATION CONTAINED IN THIS E-MAIL AND ANY ATTACHED DOCUMENTATION IS
INTENDED FOR THE USE OF THE ADDRESSEE ONLY, IS CONFIDENTIAL AND MAY BE
LEGALLY PRIVILEGED.  ANY DISSEMINATION, DISTRIBUTION, COPYING, OR USE OF
THIS COMMUNICATION WITHOUT PRIOR PERMISSION OF THE SENDER IS STRICTLY
PROHIBITED.  If you are not the intended recipient, you must not disclose,
copy, or distribute, or use the information contained in this e-mail.  If
you have received this e-mail in error, please notify us immediately by
return email.

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki
image001.jpg (image/jpeg, 6.4 KB) - not displayed
smime.p7s (application/x-pkcs7-signature, 3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.