Configure Services and Policies for Service Networks
After delivering a service network, configure NAT, load balancing, and network policies as needed. NAT translates traffic addresses on a Tier-0 or Tier-1 gateway. Load balancing distributes TCP or UDP traffic through a VIP on a Tier-1 gateway to pool members. QoS profiles control traffic, and SpoofGuard profiles prevent address spoofing.
Before configuring services and policies, complete Fabric, gateway, and segment configuration for the site. For NAT, select a rule type based on the access direction. For load balancing, create resources in dependency order: health monitors and profiles, server pools, pool members, and virtual servers.
Before combining a DNAT rule on a Tier-0 gateway with a load balancing service on a Tier-1 gateway, confirm that the network segments and routes meet the requirements. For details, see Create a DNAT Rule.
NAT
NAT rules are associated with a Tier-0 gateway or Tier-1 gateway. Before you create a rule, verify that the target gateway is deployed, select a rule type based on the traffic direction, and prepare the IPv4 addresses, protocol, and ports required for translation.
| Rule Type | Use Case | Translation |
|---|---|---|
| SNAT | Access from an internal network to an external network | Translates the source IP of internal traffic to the source IP used for outbound traffic. |
| DNAT | Access from an external network to an internal service | Translates the destination IP used for external access to the internal service IP and can also translate the destination port. |
| Reflexive NAT | One-to-one bidirectional mapping between an internal IP and an external IP | Creates a bidirectional translation between one internal IPv4 address and one external IPv4 address. |
Create an SNAT Rule
Create an SNAT rule to translate the source IP of matching traffic to an IP used for outbound traffic.
- A Tier-0 gateway or Tier-1 gateway for the SNAT rule is created and deployed.
- The internal IPv4 address or CIDR that requires external access and the translated IPv4 address used for outbound traffic are available.
The SNAT rule appears on the NAT page. Check Address Translation, State, and Deployment Status to verify the configuration.
Create a DNAT Rule
Create a DNAT rule to translate the destination IP or port of external traffic to an internal service IP or port.
- A Tier-0 gateway or Tier-1 gateway for the DNAT rule is created and deployed.
- The IPv4 address for external access and the IPv4 address of the internal service are available. If port translation is required, prepare the external and internal service ports.
Note: When a DNAT rule on a Tier-0 gateway forwards traffic to the VIP of a load balancing virtual server on a Tier-1 gateway, place the Tier-0 external network and the Tier-1 load balancing service network on different segments and do not use identical or overlapping CIDRs. Make sure that the associated gateways can reach the backend network and that the forward and return paths are symmetric. If the two service networks use the same segment or CIDR, TCP connections might fail.The DNAT rule appears on the NAT page. Check Address Translation, State, and Deployment Status to verify the configuration.
Create a Reflexive NAT Rule
Create a Reflexive NAT rule to establish a one-to-one bidirectional translation between an internal IP and an external IP.
- A Tier-0 gateway or Tier-1 gateway for the Reflexive NAT rule is created and deployed.
- The internal and external IPv4 addresses for the one-to-one mapping are available.
The Reflexive NAT rule appears on the NAT page. Address Translation displays the source and translated IPs as a bidirectional mapping.
Manage NAT Rules
As network requirements change, you can edit the translation settings and match criteria of a NAT rule, or enable, disable, or delete the rule. Enable, disable, and delete operations support both individual and bulk actions.
Before you modify a rule, use its Gateway, Rule Type, and Address Translation values to verify that you selected the correct rule and avoid affecting other address translation services.
Edit a NAT Rule
Modify the basic information, apply-to interface, translation settings, or match criteria of a NAT rule.
The NAT rule that you want to modify is created.
The updated rule appears on the NAT page. Check Address Translation, State, and Deployment Status to verify the update.
Enable or Disable NAT Rules
Enable or disable NAT rules to control whether they process NAT traffic.
The NAT rules that you want to enable or disable are created.
State on the NAT page shows the new state. After the rule is deployed, check Deployment Status to verify the operation.
Delete NAT Rules
Delete NAT rules that are no longer required so that they no longer provide address translation.
- Verify that the target rules no longer carry service traffic.
- Use the gateway, rule type, and address translation values to verify the scope of the deletion.
The rules are removed from the NAT page.
Load Balancing
Load balancing provides Layer 4 access to TCP or UDP services through a VIP, protocol, and listener port, and forwards traffic to pool members in a server pool. Load balancing resources are associated with a Tier-1 gateway.
| Resource | Purpose | Requirement |
|---|---|---|
| Health Monitor | Checks whether the service on a pool member is available. | Optional. Create before the server pool. |
| Profile | Maintains sessions based on the source IP, source port, destination IP, or destination port. | Optional. Create before the virtual server. |
| Server Pool | Associates with a Tier-1 gateway and groups pool members that receive traffic. | Required. |
| Pool Member | Consists of the IP address of a segment port and a service port. | Required. Add after the server pool is created. |
| Virtual Server | Defines the VIP, listener port, and protocol that clients use and associates them with a server pool. | Required. Create last. |
For a minimum configuration, you can omit the health monitor and profile. Create a server pool, add pool members, and then create a virtual server.
Create a Health Monitor
To monitor pool member availability, create a health monitor and associate it with a server pool.
The health monitor appears on the Health Monitors tab and is available when you create a server pool.
Create a Load Balancing Profile
To configure session persistence, create a profile that forwards traffic with the same characteristics to the same pool member.
The profile appears on the Profiles tab and is available when you create a virtual server.
Create a Server Pool and Add Pool Members
Create a server pool associated with a Tier-1 gateway and add pool members that receive traffic.
- A Tier-1 gateway for load balancing is created and deployed.
- A service network connected to the Tier-1 gateway is created, and the segment ports of the backend VMs have IPv4 addresses.
The pool members appear on the Pool Members tab for the server pool. Verify each member's IP Address, Port, VM Name, and NIC Name, and verify that State is Enabled.
Create a Virtual Server
Create a virtual server that receives client traffic on a VIP and listener port and forwards the traffic to an associated server pool.
- A server pool is created and contains at least one enabled pool member.
- The VIP, listener port, and protocol that clients use to access the load balancing service are available.
The virtual server appears on the Virtual Servers tab. The list displays VIP, Listener Port, Protocol, Tier-1 Gateway, Server Pool, Profile, and State.
Manage Load Balancing Resources
As service requirements change, you can modify virtual servers, server pools, pool members, health monitors, and profiles. You can also enable or disable virtual servers and pool members to control whether they receive or forward traffic.
Before changing the association between a segment that contains pool members and a Tier-1 gateway, disable or delete the affected pool members. After the change, access the VIP from a client to verify load balancing connectivity.
Before you delete a load balancing resource, check its resource relationships and the impact on services. To manage multiple resources, use the bulk actions available on the resource page.
Modify Load Balancing Configuration
Modify the basic information and service settings of load balancing resources.
The load balancing resource that you want to modify is created.
The resource page displays the updated configuration. For a virtual server or pool member, also verify that State meets the service requirements.
Control Load Balancing Traffic
Enable or disable virtual servers and pool members to control load balancing traffic.
The virtual servers or pool members that you want to enable or disable are created.
State on the Virtual Servers or Pool Members page shows the new state.
Prepare Pool Members for Backend Network Changes
Disable or delete affected pool members before you detach their segment from a Tier-1 gateway.
- Identify the segment to change and the affected virtual servers, server pools, and pool members.
- Determine the impact of the network change on load balancing services and schedule an appropriate maintenance window.
Detaching a segment from a Tier-1 gateway does not automatically disable or delete the pool members on that segment. After the segment is detached, Pool Member Status on the virtual server details page might continue to show Up even when clients can no longer access the backend service through the VIP.
Note: Pool Member Status and the pool member State represent different information. After a network topology change, access the VIP from a client to verify that the load balancing service is available. Do not rely solely on Pool Member Status.- Navigate to , and select the Virtual Servers tab.
- Click the target virtual server name. On the virtual server details page, check Pool Member Status and identify the affected pool members by their IP addresses and ports.
- Return to the Load Balancing page, select the Server Pools tab, click the target server pool name, and select the Pool Members tab.
-
Process the affected pool members according to the planned network change.
- For a temporary detachment, select Disable from the Actions column for the target pool member. To process multiple pool members, select them, click Bulk Action, and select Disable.
- For a permanent detachment, select Delete from the Actions column for the target pool member. To process multiple pool members, select them, click Bulk Action, and select Delete.
- In the confirmation dialog box, verify the target pool members and confirm the operation.
- Verify that temporarily disabled pool members show State as Disabled, or that permanently deleted pool members are removed from the page.
The affected pool members no longer participate in traffic distribution for the server pool or are removed from the server pool.
- After you process the pool members, follow the applicable network management workflow to detach the segment from the Tier-1 gateway.
- After the network change, access the VIP from a client and verify that the load balancing service meets the service requirements.
Delete Load Balancing Resources
Delete virtual servers, server pools, pool members, health monitors, or profiles that are no longer required.
- Verify that the target resources no longer carry service traffic.
- Check the relationships between the target resources and other load balancing resources.
The resources are removed from the corresponding resource page.
Configure Network Policies
Network Policies include Router QoS, Segment QoS, and SpoofGuard profiles. ZNS administrators can create profiles as needed and select them for gateways, segments, or service networks.
QoS profiles control network traffic bandwidth and burst capability. SpoofGuard profiles prevent VM IP/MAC address spoofing.
Create a Router QoS Profile
The Router QoS Profile page configures traffic shaping rules in the router direction.
After the profile is created, you can view profile name, direction, action, default profile, bandwidth, burst size, description, and creation time in the list.
Note: Default profiles cannot be deleted. Before you delete a profile, confirm that it is no longer used by service gateways.Create a Segment QoS Profile
The Segment QoS Profile page configures ingress and egress rate limiting rules for segments.
After the profile is created, you can view default profile, ingress average bandwidth, ingress peak bandwidth, ingress burst size, egress average bandwidth, egress peak bandwidth, egress burst size, description, and creation time in the list.
Note: Default profiles cannot be deleted. Before you delete a profile, confirm that it is no longer used by service segments.Create a SpoofGuard Profile
The SpoofGuard Profile page prevents VM IP/MAC address spoofing.
After the profile is created, you can view profile name, state, default profile, description, and creation time in the list.
Note: Default profiles cannot be deleted. Before you delete a profile, confirm that it is no longer used by service networks.