{"id":461,"date":"2013-07-26T17:26:03","date_gmt":"2013-07-26T15:26:03","guid":{"rendered":"http:\/\/dety.net.ua\/?p=461"},"modified":"2013-07-26T17:26:03","modified_gmt":"2013-07-26T15:26:03","slug":"load-balancer-for-exchange","status":"publish","type":"post","link":"https:\/\/dety.net.ua\/?p=461","title":{"rendered":"Load Balancer for Exchange"},"content":{"rendered":"<p>I was needed in a cheep software NLB and found this article: <a href=\"http:\/\/marksmith.netrends.com\/Lists\/Posts\/Post.aspx?ID=111\" target=\"_blank\">http:\/\/marksmith.netrends.com\/Lists\/Posts\/Post.aspx?ID=111<\/a><\/p>\n<blockquote>\n<div>\n<div>\n<div dir=\"\">\n<div>\n<p>In this article I will show you how to build an open-source, Linux (CentOS) based load balancer using the Direct Server Return (DSR) method of load balancing with the Linux Virtual Server (LVS) package and the Piranha web GUI. Let me first say that I have a deep knowledge of the Windows OS but my Linux knowledge is, well, about as deep as a kiddie pool after a day of splashing by my kids! So, for those of you who are Linux gurus, please feel free to provide comments, suggestions, or just laugh! In any event, my goal in building this configuration is to give you a possible solution for your labs, or if you have a solid Linux background and operations team, possibly even offer a production solution for Exchange deployments. The other main reason for me researching this solution is that all too many times I see customers looking at Windows Network Load Balancing (NLB) as an HA solution for CAS. If you&#8217;re considering Windows NLB I would highly recommend that you don&#8217;t. There are a number of fellow Exchange experts that have outlined the limitations so here&#8217;s a quick technical recap of the downsides of Windows NLB in an Exchange 2010 deployment.<\/p>\n<ul>\n<li>You cannot run Windows NLB on a DAG member. See: <a href=\"http:\/\/support.microsoft.com\/kb\/954420\">http:\/\/support.microsoft.com\/kb\/954420<\/a> This means that the number of Exchange servers in your design will increase since you&#8217;ll need to break out CAS to its own OS. Let&#8217;s quickly do the math. This means you just added two or more additional Windows, Exchange, Forefront\/AV, etc. licenses. You could have put that money toward a hardware\/virtual load balancer and combined the Exchange roles which will reduce your operational TCO and give you a better chance of maintaining your messaging SLA&#8217;s.<\/li>\n<li>Windows NLB is only host aware and not application layer aware. This means, for example, that if IIS crashes but the OS doesn&#8217;t, Windows NLB may continue to direct OWA, EWS, etc. traffic to the failed CAS.<\/li>\n<li>Windows NLB is not a way to make friends with your network team. In most instances, it will port flood your switches. So, in order to get around this you&#8217;ll need to implement one of the kludge fixes like <a href=\"http:\/\/www.cisco.com\/en\/US\/products\/hw\/switches\/ps708\/products_configuration_example09186a0080a07203.shtml\">this<\/a> which creates complexity for your network team.<\/li>\n<li>Windows NLB does a poor job of persistency and is based on source IP only. Although I&#8217;m not 100% sure, I suspect Windows NLB is using a hash table of the source IP network rather than using a true \/32 bit mask table in memory. In short, this means that if your clients all come from the same subnet, it can end up directing an uneven load to one CAS.<\/li>\n<li>There are known issues using Windows NLB with virtual machines that require <a href=\"http:\/\/kb.vmware.com\/selfservice\/microsites\/search.do?language=en_US&amp;cmd=displayKC&amp;externalId=1006558\">special configuration<\/a>.<\/li>\n<\/ul>\n<p>Therefore, my first recommendation is to invest in a commercial hardware load balancer. There are a number of partners that are now part of the <a href=\"http:\/\/technet.microsoft.com\/en-us\/office\/ocs\/cc843611.aspx\">Microsoft UC Load Balancer Interoperability Qualification program.<\/a> In addition to the vendors in this program I&#8217;ve personally had great success with F5 ($$$), Radware ($$), A10($$), Foundry ServerIron (Brocade), and both the hardware versions and the Virtual Machine flavors of the Kemp Technologies Load Masters ($). If your load allows (the SMB), I would definitely test the <a href=\"http:\/\/www.kemptechnologies.com\/us\/server-load-balancing-appliances\/virtual-load-balancers\/vlm-overview.html\">Kemp Virtual Load Balancer<\/a>.<\/p>\n<p>With that said, hopefully this article will help provide you with a better understanding around how load balancers work and may even offer a very low cost open-source option to your Exchange deployment or labs. So let&#8217;s get into the weeds!<\/p>\n<p>Why DSR? <a href=\"http:\/\/www.linuxvirtualserver.org\/VS-DRouting.html\">DSR or Direct Service Return or Direct Routing<\/a> takes the least amount of resources to load balance traffic to your real servers. In short it works like this:<\/p>\n<ul>\n<li>The client sends the TCP packet to the Virtual IP (VIP) of the load balancer e.g. 10.10.11.19.<\/li>\n<li>When the ARP request is made by the client or local router, the load balancer responds with its MAC address e.g. AB-CD-EF-G1-23-45<\/li>\n<li>The load balancer then takes the packet and &#8216;flips&#8217; <strong>only<\/strong> the MAC address to be the MAC of one of the real (CAS) servers. E.g. 12-34-56-78-90-AB<\/li>\n<li>The real CAS server then accepts the packet and responds directly to the client. i.e. the packet does not route back through the load balancer.<\/li>\n<\/ul>\n<p>According to one vendor&#8217;s <a href=\"http:\/\/loadbalancer.org\/load_balancing_methods.php\">documents<\/a> this typically will run about 8 times faster than using a NAT load balancing method for HTTP traffic, 50 times faster for terminal services, and even faster for streaming media or FTP. The other advantage is that DSR provides client transparency to the real server. This means the real server (CAS) will log and see the source IP address of the actual Outlook or browser client in its logs where using NAT will result in the source IP always appearing as the VIP of the load balancer.<\/p>\n<p>The downside in this method is that it runs at Layer 4 of the <a href=\"http:\/\/en.wikipedia.org\/wiki\/OSI_model\">OSI model<\/a> which means that you&#8217;re limited to source IP as the method to provide affinity, or persistency between the client and the real server (see <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/ff625247.aspx\">http:\/\/technet.microsoft.com\/en-us\/library\/ff625247.aspx#affinity<\/a> for more information). However, keeping to the scope of this article, if you were considering Windows NLB, you probably don&#8217;t have the load that would warrant the need for cookie based affinity which is only available using a Layer 7 hardware proxy.<\/p>\n<p>The other downside of using DSR is that since it only flips the MAC address of the packet i.e. the destination IP address remains the VIP of the load balancer, the real server (CAS) will not accept the packet. Therefore, we need a way for Windows to accept this packet with an IP address that isn&#8217;t its own. To address this issue we need to perform extra configuration on CAS by installing the Microsoft Loopback adapter and assign the IP address of the Load Balancer&#8217;s VIP. We also need to make sure that CAS does not respond to ARP requests of the VIP \u2013 that should only be done by the actual Load Balancer.<\/p>\n<p>The Lab Layout:<\/p>\n<p><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci1.png\" \/><\/p>\n<h1>Configuring our Windows Servers.<\/h1>\n<ol>\n<li>Prepare our Exchange CAS servers by configuring the Microsoft Loopback Adapter. Open Device Manager, right click on server name, install legacy device.<\/li>\n<li><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci2.png\" \/><\/li>\n<li><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci3.png\" \/><\/li>\n<li><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci4.png\" \/><\/li>\n<li>\n<div>Rename the loopback adapter to &#8216;loopback&#8217; and the &#8216;regular&#8217; interface to &#8216;net&#8217;.<\/div>\n<p><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci5.png\" \/><\/li>\n<li>Configure the loopback adapter. Unbind all protocols\/services except for IPv4<\/li>\n<li>\n<div><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci6.png\" \/><\/div>\n<\/li>\n<li>Configure the IP of the loopback adapter with the VIP of the Load balancer and no default gateway.<\/li>\n<\/ol>\n<ol>\n<li><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci7.png\" \/><\/li>\n<li>Click Advanced and uncheck automatic metric. Set the metric to 254 which stops the interface from responding to arp requests.<\/li>\n<li><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci8.png\" \/><\/li>\n<li>On the DNS tab, uncheck &#8216;Register this connection&#8217;s address in DNS&#8217;<\/li>\n<li><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci9.png\" \/><\/li>\n<li>\n<div>Now disable weak host receiving (note the interface names must match &#8212; net and loopback)<\/div>\n<ol>\n<li>netsh interface ipv4 set interface &#8220;net&#8221; weakhostreceive=enabled<\/li>\n<li>netsh interface ipv4 set interface &#8220;Loopback&#8221; weakhostreceive=enabled<\/li>\n<li>netsh interface ipv4 set interface &#8220;Loopback&#8221; weakhostsend=enabled<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h1>Building Our Load Balancer<\/h1>\n<ol>\n<li>Download the Centos 5.5 ISO files from here: <a href=\"http:\/\/isoredirect.centos.org\/centos\/5\/isos\/x86_64\/\">http:\/\/isoredirect.centos.org\/centos\/5\/isos\/x86_64\/<\/a><\/li>\n<li>\n<div>Create a VM in Hyper-V with the following specs:<\/div>\n<ol>\n<li>512MB RAM<\/li>\n<li>Remove all network adapters (Synthetic and Legacy)<\/li>\n<li>Remove the SCSI adapter<\/li>\n<li>10-20GB VHD<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci10.png\" \/><\/li>\n<\/ol>\n<\/li>\n<li>Boot the VM and when prompted for the install type, select a &#8220;linux text&#8221; install type.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci11.png\" \/><\/li>\n<li>I skip the media test but you can run it if you choose.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci12.png\" \/><\/li>\n<li>Follow the prompts, selecting the languages, keyboard, etc.<\/li>\n<li>When prompted select yes to initialize the virtual HD.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci13.png\" \/><br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci14.png\" \/><\/li>\n<li>Select OK on the partition type (leave default options) unless you really want to customize these.<\/li>\n<li>Continue through the partition and format warnings, select your time zone, and enter a root password.<\/li>\n<li>\n<div>Since we want to run a slim deployment of Centos, we&#8217;ll want to remove all of the GUI options so at the package selection, remove the following:<\/div>\n<ol>\n<li>Desktop \u2013 Gnome (all others should be disabled by default)<\/li>\n<li>SELECT the Customize software selection<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci15.png\" \/><\/li>\n<li>Click ok<\/li>\n<\/ol>\n<\/li>\n<li>Select the Base, Development Tools and Editors, Uncheck Dialup Networking Support and Text based Internet. The critical item here is the addition of the Development Tools which is required for the Hyper-V Linux Integration components.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci16.png\" \/><\/li>\n<li>The install will begin \u2013 make sure you have all of the CD or DVD iso required for the install.<\/li>\n<li>While the install is running, download the Hyper-V Linux Integration Services here: <a href=\"http:\/\/www.microsoft.com\/downloads\/en\/details.aspx?displaylang=en&amp;FamilyID=eee39325-898b-4522-9b4c-f4b5b9b64551\">http:\/\/www.microsoft.com\/downloads\/en\/details.aspx?displaylang=en&amp;FamilyID=eee39325-898b-4522-9b4c-f4b5b9b64551<\/a><\/li>\n<li>After Centos installs and reboots, the setup agent will run. Run the firewall configuration tool.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci17.png\" \/><br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci18.png\" \/><\/li>\n<li>Set the Security Level to Disabled and SELinux to Disabled.<\/li>\n<li>Although this is not critical, I run the System Services Tool and disable the Bluetooth, CUPS (Printing Services) and Sendmail services.<\/li>\n<li>Quit and you will be in the console shell. Insert the Hyper-V Integration Services ISO into the VM.<\/li>\n<li>\n<div>Enter the following:<\/div>\n<ol>\n<li>mkdir \/media\/cdrom<\/li>\n<li>mount \/dev\/cdrom \/media\/cdrom<\/li>\n<li>mkdir \/opt\/hypervsvc<\/li>\n<li>cp \u2013R \/media\/cdrom\/* \/opt\/hypervsvc<\/li>\n<li>cd \/opt\/hypervsvc<\/li>\n<li>make<\/li>\n<li>make install<\/li>\n<li>shutdown now<\/li>\n<\/ol>\n<\/li>\n<li>Once the server has shutdown, power it off and add a Synthetic Network adapter to the VM, select &#8220;Enable spoofing of MAC addresses&#8221;, and then power it back up.<br \/>\nNOTE: I use VLANs in my lab so the use of VLANs, or VLAN 11 in the screen grab below is not critical and will depend on your environment.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci19.png\" \/><\/li>\n<li>When Centos boots, log in as root and confirm that a new Ethernet interface is active and, assuming you&#8217;re running DHCP on your network, you have an IP address.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci20.png\" \/><\/li>\n<li>Now let&#8217;s give our synthetic Ethernet interface a static IP by running system-config-network which will bring up the network setup assistant. Edit the seth0 interface and give it the static IP \u2013 in my lab it&#8217;s 10.10.11.20\/24<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci21.png\" \/><\/li>\n<li>Configure the DNS settings then save &amp; quit.<\/li>\n<li>\n<div>Restart the network service by entering:<\/div>\n<ol>\n<li>service network restart<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci22.png\" \/><\/li>\n<li>confirm the ip binding by entering ifconfig<\/li>\n<\/ol>\n<\/li>\n<li>\n<div>Next we&#8217;ll install the Linux Virtual Server and Piranha (the Load Balancer GUI) packages. It is critical that you have Internet access at this time so the packages can be downloaded. So let&#8217;s begin by entering:<\/div>\n<ol>\n<li>yum install ipvsadm<\/li>\n<li>yum install piranha<br \/>\nNOTE: You&#8217;ll be asked to confirm the download of the packages. Type yes.<\/li>\n<\/ol>\n<\/li>\n<li>\n<div>Now we&#8217;ll configure the installed services to start automatically. Enter:<\/div>\n<ol>\n<li>chkconfig pulse on<\/li>\n<li>chkconfig piranha-gui on<\/li>\n<li>chkconfig httpd on<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci23.png\" \/><\/li>\n<\/ol>\n<\/li>\n<li>\n<div>Next we&#8217;ll configure a password for Piranha. Enter:<\/div>\n<ol>\n<li>piranha-passwd<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci24.png\" \/><\/li>\n<\/ol>\n<\/li>\n<li>\n<div>Now let&#8217;s enable IP forwarding using the command:<\/div>\n<ol>\n<li>echo 1 &gt; \/proc\/sys\/net\/ipv4\/ip_forward<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci25.png\" \/><\/li>\n<\/ol>\n<\/li>\n<li>\n<div>Now let&#8217;s start the Piranha GUI. Note: during the setup agent we disabled the SELinux Enforcement. If that wasn&#8217;t done you&#8217;ll get an error when starting the service: <em>Starting piranha-gui: (13)Permission denied: make_sock: could not bind to address [::]:3636<br \/>\n(13)Permission denied: make_sock: could not bind to address 0.0.0.0:3636<br \/>\nNo listening sockets available, shutting down<br \/>\nUnable to open logs<br \/>\n<\/em>So, let&#8217;s configure using the commands:<\/div>\n<ol>\n<li>setenforce 0<\/li>\n<li>service httpd start<\/li>\n<li>service piranha-gui start<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci26.png\" \/><\/li>\n<\/ol>\n<\/li>\n<li>Now let&#8217;s open a browser and navigate to the Piranha GUI over port 3636. In my example, it is <a href=\"http:\/\/10.10.10.20:3636\">http:\/\/10.10.10.20:3636<\/a><br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci27.png\" \/><\/li>\n<li>Now let&#8217;s configure the load balancer. We&#8217;ll going to use DSR so click on the Global Configuration tab and configure as follows:<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci28.png\" \/><br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci29.png\" \/><\/li>\n<li>Next we&#8217;ll create the VIP. Click on Virtual Servers then &#8220;Add&#8221;. Then select the VIP with the radio button and click &#8220;Edit&#8221;.<\/li>\n<li>Let&#8217;s define our TCP 443 virtual server. Call this VIP &#8220;Exchange-443&#8221;, set the application port to TCP 443, the VIP and subnet mask. It is important that you modify the interface to <strong>s<\/strong>eth0:1 (synthetic Ethernet). Modify the service timeout to 30 seconds, use Round-Robin and a persistence setting of 4 hours \u2013 14400 seconds, and a persistence network mask of 255.255.255.255 (an individual host).<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci30.png\" \/><\/li>\n<li>Now let&#8217;s define our real servers. Click on the real server link, then click the &#8220;ADD&#8221; button twice (for 2 CAS servers in our case). Then select the first with the radio button and click edit.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci31.png\" \/><\/li>\n<li>Enter the real IP address of the CAS1 server, click accept. Then repeat the process for the second CAS server.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci32.png\" \/><\/li>\n<li>Now click on the Real Server link again and confirm that the real servers are configured properly.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci33.png\" \/><\/li>\n<li>Next activate the real servers by clicking on each server&#8217;s radio button then click the &#8220;(DE)ACTIVATE&#8221; button.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci34.png\" \/><\/li>\n<li>Click on the Monitoring scripts link and then click the blank send and blank expect button then the Accept button. We&#8217;ll start with a basic TCP Bind as our health check and then define a &#8220;smarter&#8221; method to monitor OWA later in this article. . Using Blank Send\/Expect will just use a TCP bind to determine health.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci35.png\" \/><\/li>\n<li>Now let&#8217;s activate the VIP by clicking on the Virtual Servers tab, selecting our &#8220;Exchange-443&#8221; VIP and click the &#8220;(DE)ACTIVATE&#8221; button.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci36.png\" \/><\/li>\n<li>\n<div>Now go back to the Centos shell and restart the pulse service. Note: If this is the first time you&#8217;ve configured the load balancer, the pulse service will show as failed when shutting down.<br \/>\nUse the command:<\/div>\n<ol>\n<li>service pulse restart<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci37.png\" \/><\/li>\n<\/ol>\n<\/li>\n<li>Now let&#8217;s check the status of the VIP. Go back to the Piranha web GUI and click on Control\/Monitoring. If everything is working you&#8217;ll see the VIP (10.10.11.19) bound to TCP 443 and routing to both of our real servers. If the real servers are not listed then the health check is failing.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci38.png\" \/><\/li>\n<li>Let&#8217;s test out the VIP. <a href=\"https:\/\/10.10.11.19\/owa\">https:\/\/10.10.11.19\/owa<\/a> The cert error is because of the name mis-match but the VIP is working.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci39.png\" \/><\/li>\n<li>Let&#8217;s test a real server failure. In Hyper-V, I disconnected my CAS VM from the Virtual Network which will simulate it dropping off of the network. Wait for the health check period to pass and we&#8217;ll see the real server drop off the routing table:<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci40.png\" \/><\/li>\n<li>Now that we&#8217;ve seen that the health checks work, re-enable the network settings on our CAS server to bring both online. Now let&#8217;s finish configuring the rest of the TCP ports (virtual servers) that we&#8217;ll need to load balance Exchange. In my Exchange configurations, I statically configure TCP port 7575 for the RPC Client Access Service and TCP 7576 for the Address Book Service. We&#8217;ll also need TCP 135 for the RPC endpoint mapper and TCP 80 (for the http to https redirect). Configure the persistency timeout values for 135, 7575, 7576, and 80 to be 300 seconds but TCP 443 should be 4 hours to accommodate for private computer OWA sessions. When you&#8217;ve completed all the virtual servers tab should look like this<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci41.png\" \/><\/li>\n<li>\n<div>After the config changes are made, restart the pulse service using &#8220;service pulse restart&#8221;. Then we&#8217;ll check the monitoring status. The status should show all TCP ports routing and healthy:<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci42.png\" \/><\/div>\n<\/li>\n<\/ol>\n<h1>Implementing a smarter health check for Outlook Web.<\/h1>\n<p>In our initial implementation of the VIP that load balances TCP 443 (OWA, ECP, etc) we only used a simple TCP bind to test if the server is healthy. However, what happens if there is a problem within an app pool or an underlying .NET issue? In that case IIS will most likely still respond to the TCP bind, but the application may not be available (OWA, ECP etc). So let&#8217;s add some smarts to our healthcheck and look for something in the HTTP stream to check for. For this solution we&#8217;ll use the wget command to open an HTTPS session and look for the string Outlook in the Forms Based Auth. You can enhance this test but the basic setup should give you the idea of health checking.<\/p>\n<ol>\n<li>Change directory to \/usr\/local\/bin:<br \/>\ncd \/usr\/local\/bin<br \/>\nNow hold on Windows guys, we&#8217;re going back to the ANSI BBS days!<\/li>\n<\/ol>\n<p>Open up the Centos shell and run vi \u2013 the command line text editor using the following:<br \/>\nvi lvs_check_owa<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci43.png\" \/><br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci44.png\" \/><\/p>\n<ol>\n<li>Next type &#8220;I&#8221; (lower case i) and enter insert mode.<br \/>\nenter the following bash script:<br \/>\n#!\/bin\/bash<br \/>\nLINES=`wget \u2013q \u2013O &#8211; &#8211;no-check-certificate https:\/\/$1:$2\/owa`<br \/>\nif [[ $LINES == *utlook* ]]; then<br \/>\necho &#8220;OK&#8221;<br \/>\nelse<br \/>\necho &#8220;FAILURE&#8221;<br \/>\nfi<br \/>\nexit 0<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci45.png\" \/><\/li>\n<li>Once you have entered the text, hit the ESC key then &#8220;:x&#8221; to save the file.<\/li>\n<li>Next set the permissions on the file so it can be executed using the command:<br \/>\nchmod u+x lvs_check_owa<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci46.png\" \/><\/li>\n<li>Now test the script by calling it and passing the IP of one of our real servers and TCP 443:<br \/>\nlvs_check_owa 10.10.11.78 443<br \/>\nIf all goes well we should have an &#8220;OK&#8221; returned.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci47.png\" \/><\/li>\n<li>Now let&#8217;s configure the load balancer to use the script. Open back up the Piranha web GUI, select the Exchange_443 VIP&#8217;s radio button and click &#8216;edit&#8217;.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci48.png\" \/><\/li>\n<li>In the sending program field enter:<br \/>\n\/usr\/local\/bin\/lvs_check_owa %h %p<br \/>\nThen enter OK to the Expect field and click Accept.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci49.png\" \/><\/li>\n<li>Now go back to the Centos shell and restart the pulse service: &#8220;service pulse restart&#8221;<\/li>\n<li>Click on the Control\/Monitoring link and review that the 443 VIP is running and checking health by calling our lvs_check_https script.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1911_LoadBalanci50.png\" \/><\/li>\n<\/ol>\n<h1>Adding High Availability to the Load Balancing Solution<\/h1>\n<p>Built into LVS is the ability to create an HA Pair (Active\/Passive). We&#8217;ll leverage some features of virtualization to deployment this for this article. If, however, you were going to deploy this solution in a virtualized environment, you may simply want to rely on the integrated features of Live Migration, Vmotion, and\/or VM clustering to provide HA for your LVS rather than actually deploying a LVS pair. If you wanted to deploy this on physical hardware then the process would be similar to what I&#8217;ve outlined in the VM environemtn for building two LVS servers. First, let&#8217;s review how the lab environment will change with the addition of our HA pair. We&#8217;ll add a second VLS which can be an owner for the floating VIP we already created.<\/p>\n<p><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci1.png\" \/><\/p>\n<ol>\n<li>Let&#8217;s first clone the Centos LVS Virtual Machine that we already built. Shut down linux using the command: &#8216;poweroff&#8217; once the VM is powered off, export the virtual machine.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci2.png\" \/><\/li>\n<li>Once the export has completed, rename the existing Virtual Machine \u2013 in our case we&#8217;ll simply add &#8220;01&#8221; to the VM name.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci3.png\" \/><\/li>\n<li>Next we&#8217;ll import the exported VM. Check the &#8220;Copy the virtual machine (create a new unique ID)&#8221; and optionally check &#8220;Duplicate all files so the same virtual machine can be imported again&#8221;<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci4.png\" \/><\/li>\n<li>After our duplicated VM has imported, we&#8217;ll rename the import \u2013 in my case I&#8217;ll simply add &#8220;02&#8221; to the VM name.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci5.png\" \/><\/li>\n<li>Next, power up Centos Load Balancer 02, log in as root, and enter the command &#8216;system-config-network&#8217; and change the IP address. Per our lab diagram, we&#8217;ll use 10.10.11.21<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci6.png\" \/><\/li>\n<li>Save and quit the config utility and then restart the network stack using the command &#8216;service network restart&#8217; then confirm the IP config by entering &#8216;ifconfig&#8217;.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci7.png\" \/><\/li>\n<li>Now power up the Centos LVS 01 server and log in as root. Now open the Piranha GUI and click on the redundancy tab, enter the 02 server&#8217;s IP address, check Monitor NIC links for failures, Syncdaemon and click the enable button.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci8.png\" \/><\/li>\n<li>Now go back to the Centos shell of the 01 server and copy the config file to the 02 server by entering the command:<br \/>\nscp \/etc\/sysconfig\/ha\/lvs.cf <a href=\"mailto:root@10.10.11.21:\/etc\/sysconfig\/ha\/lvs.cf\">root@10.10.11.21:\/etc\/sysconfig\/ha\/lvs.cf<\/a><br \/>\nIf you are prompted to confirm the certificate thumbprint enter yes.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci9.png\" \/><\/li>\n<li>Now restart the pulse service on the 01 server and then the 02 server using the command &#8220;service pulse restart&#8221;.<br \/>\nNOTE: In my HyperV testing I receive the error message &#8220;IPVS: Error setting outbound mcast interface&#8221;. I believe this is due to the HyperV network stack but I haven&#8217;t confirmed that yet. In any event, the HA pair does fail over properly, as you&#8217;ll see below.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci10.png\" \/><br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci11.png\" \/><\/li>\n<li>Now log back into the Piranha interface on both the 01 and 02 server. If the server is acting as the passive node the routing table will be empty.<br \/>\nIf the routing table is present (like the lower screen grab) the router is the active node.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci12.png\" \/><br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci13.png\" \/><\/li>\n<li>Now that we know that our 02 node is the active node we&#8217;ll start a running ping to the VIP from a client machine.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci14.png\" \/><\/li>\n<li>Now let&#8217;s power off the 02 node (the active node). Watch the running ping \u2013 4 pings are lost (about 20 seconds) while the passive node lets the active node check time out.\n<p><img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci15.png\" \/><\/li>\n<li>Now go back to the 01 server&#8217;s Piranha GUI and click on the &#8216;Control\/Monitoring&#8217; link. You&#8217;ll notice that the routing table is now active.<br \/>\n<img decoding=\"async\" alt=\"\" src=\"http:\/\/marksmith.netrends.com\/Lists\/Photos\/120210_1915_LoadBalanci16.png\" \/><\/li>\n<\/ol>\n<p>We&#8217;ve now built and tested our LVS HA pair!<\/p>\n<h1>Conclusion<\/h1>\n<p>I hope this article has provided some insight into how load balancers work, how to configure them with Exchange 2010, and also to provide you a possible solution in your Exchange lab and, if you have a good comfort level with Linux, possibly your production environment. However, I would highly recommend consulting a skilled Linux \/ LVS expert before even considering this as a production solution.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/blockquote>\n<div>\n<div>\n<div dir=\"\">\n<div>\n<p>My 5 cents:<\/p>\n<p>Coming soon<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>I was needed in a cheep software NLB and found this article: http:\/\/marksmith.netrends.com\/Lists\/Posts\/Post.aspx?ID=111 In this article I will show you how to build an open-source, Linux (CentOS) based load balancer using the Direct Server Return (DSR) method of load balancing with the Linux Virtual Server (LVS) package and the Piranha web GUI. Let me first [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,13,12],"tags":[],"class_list":["post-461","post","type-post","status-publish","format-standard","hentry","category-exchange","category-novosti","category-windows"],"_links":{"self":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=461"}],"version-history":[{"count":2,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/461\/revisions"}],"predecessor-version":[{"id":463,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/461\/revisions\/463"}],"wp:attachment":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}