Configuring HALB in the RAS Console
To configure High Availability Load Balancing In the RAS console, navigate to
Farm
/ <Site> /
HALB
. On the
HALB
tab in the right pane, select the
Enable HALB
option. This will enable the remaining options and will also show the
Devices
tab. Configure the options on each tab as described below.
HALB tab options
Specify the following options in the
Virtual IP
section:
-
Select the IP version (IPV4, IPV6, or both) that you would like to use.
-
Specify the IP address (or addresses if both version are selected) and their corresponding property (subnet mask, prefix). This is the IP address that clients will connect to. This will also be a floating IP address used by this and other HALB appliances.
To load-balance normal gateway connections, select the
LB Gateway Payload
option and then click
Configure
. In the
HALB Configuration
dialog that opens, specify the following:
-
The port number that will be used by HALB appliances to forward traffic to gateways (the port configured on the gateway).
-
Select the gateways that the HALB appliance will load-balance.
-
Click
OK
.
To load-balance SSL connections, select the
LB SSL Payload
option and then click
Configure.
In the the
HALB Configuration
dialog, specify the following:
-
The port number that will be used by HALB appliances to forward traffic to gateways (443 by default).
-
In the
Mode
drop-down list, select
Passthrough
or
SSL Offloading
to specify where the SSL decryption process is performed. By default, the SSL connections are tunneled directly to gateways (referred to as passthrough) where the SSL decryption process is performed.
If you select the
SSL Offloading
mode, click
Configure
. The
SSL
dialog opens.The SSL Offloading mode requires an SSL certificate to be assigned to HALB. Specify the following options in the
SSL
dialog to configure SSL:
-
Accepted SSL Versions.
Select an SSL version.
-
Cipher Strength
. Select the cipher strength of your choice. To specify a custom cipher, select
Custom
and then specify the cipher in the
Cipher
field.
-
In the
Certificates
drop-down list, select a desired certificate. For the information on how to create a new certificate and make it appear in this list, see the
SSL Certificate Management
chapter.
The
<All matching usage>
option will use any certificate configured to be used by HALB. When you create a certificate, you specify the "Usage" property where you can select "Gateway", "HALB", or both. If this property has the "HALB" option selected, it can be used with HALB. Please note that if you select this option, but not a single certificate matching it exists, you will see a warning and will have to create a certificate first.
Click
OK
to close the
SSL
dialog.
-
Back in the
HALB Configuration
dialog, select the gateways that the HALB appliance will load-balance and click
OK
to save your changes and close the dialog.
Configure the remaining properties on the
HALB
tab:
-
Select the
Client Management
option to enable management of Windows devices connected through HALB. Click
Configure
and select gateways that will mange the devices.
-
Select the
Enable RDP UDP Data Tunneling
option to enable UDP tunneling on Windows devices.
-
The
Maximum sessions per device
property specifies the maximum number of simultaneous connections allowed. Use the default value or specify your own.
Devices tab options
Click the
Devices
tab to add HALB appliances that will be managed by this Farm. To add appliances:
-
Click
Tasks
>
Add
(or click the
+
icon) to bring up the
Add HALB Devices
dialog.
Parallels RAS is capable of detecting HALB appliances over the network and display them as a list. Selecting detected HALB appliances from this list is the preferred method for adding new appliances. If an appliance cannot be detected, you can add it manually by specifying the appliance IP address in the
IP Address
field.
-
Click
OK
to close the
Add HALB Devices
dialog. The appliance is initialized and added to the list on the
Devices
tab.
-
Finally, click
Apply
for the new HALB configuration to be applied to all added HALB appliances.
For additional information, please see the following KB article: https://kb.parallels.com/123607
|