Software Secure Access
Activity Manage

Configure Load Balancing

You can configure your Virtual Appliances behind a load balancer that meets the following requirements:

  • The load balancer is able to inject the source IP address of the client making the query in the EDNS Client Subnet (ECS) field of the DNS request sent to the VA.
  • The DNS response from the Virtual Appliance routes through the load balancer. Thus, the response to the client comes from the address of the load balancer.

This feature has specifically been qualified with the F5 BIGIP-LTM 16.1.1 version, where the F5 can inject the endpoint source IP in DNS requests that it forwards to VAs in the load balancing pool. Refer to F5 documentation on ECS injection in DNS requests when forwarding these requests to a DNS server pool.

By default, the VA does not accept DNS requests with the ECS option from any endpoint. To allow the VA to accept DNS requests with the ECS option from load balancers, the load balancer IP has to be added to the VA configuration using the following commands: