server load balancing finally works since FOS 6.4
Hi,
the Fortigate has the vip type "server-load-balance" for a while and some features eg https offloading and cookie persitence looked promising, but there was a bug in the cookie handling that spoiled it all.
Since FOS 6.4 this is fixed and we use this simple slb for a while without issues. So if you think about replacing a fully blown ADC (F5,A10,FortiADC) with this feature, the following might be interesting for you.
Features
- Supported Protocols: https, generic ssl, http, tcp, udp and generic ip
- https offloading with optional crypto tuning
- http redirect to https
- HSTS and HPKP
- secure cookies
- simple http header manipulation (via web-proxy profile)
- usable health checks
- Automation through FGs standard REST API
Limitations
- SNAT is limited to FGs interface IP
- Event logging can't show VIP or real server. Works with FAZ though
- LB Monitor Dashboard shows only (static) configured state and not the health status
- max 16 real server on 1HU devices
- health checks might be redundant if real servers are reused in multiple VIPs
Missing
Advanced ADC features like
- Content rewriting
- Scripting (irules/aflex)
- Caching
- SNI
I like this feature because we didn't need a different dedicated box with individual handling, training, contracts and all. My hope: more admins use it and someone at FTN finds time to improve at least the dashboard limitation. Why did they make a dashboard that is static???
Regards,
Dirk
