Deployment Example 2: Federation Using SAML v2

Appendix E Load Balancers

Table E–1 Load Balancer Configurations

Component  

Description 

 

Host 

Computer system that hosts all virtual servers in this deployment example. 

 

Host Name 

is-f5.siroe.com 

Load Balancer 1 

Load Balancer 2 

These load balancers are not discussed in this manual. See 1.2 System Architecture and 1.2 System Architecture for more information.

Load Balancer 3 

Access Manager Servers 

Virtual Service Address for the Access Manager Web Server instances. 

SSL is terminated at this at this load balancer before the request is forwarded to the Access Manager Servers. This load-balancer is the single point-of-failure for Access Manager and can be considered a limitation of this deployment example.  

Configured for cookie and IP— based stickiness and TCP (HTTP and LDAP) load balancing.  

External users access port 9443, while internal users will access port 90. 

 

Instance Name 

LoadBalancer-3 

 

Port Number 

90 and 9443 

 

Pool Name 

AccessManager-Pool 

 

Virtual Server and Port Number 

LoadBalancer-3.example.com:90  

 

Monitor 

HTTP 

Load Balancer 4 

Load Balancer 5 

Load Balancer 6 

These load balancers are not discussed in this manual. See 1.2 System Architecture and 1.2 System Architecture for more information.

Load Balancer 7 

Federation Manager Configuration Stores 

Virtual Service Address for the Federation Manager configuration store.  

Configured for cookie and IP-based stickiness and TCP (HTTP and LDAP) load balancing. 

 

Instance Name 

LoadBalancer-7 

 

Port Number 

389 

 

Pool Name 

federation_ds_pool 

 

Virtual Server and Port Number 

LoadBalancer-7.siroe.com:389  

 

Monitor 

LDAP-tcp 

Load Balancer 8 

Federation Manager User Data Stores 

Virtual Service Address for the Federation Manager User Data store. 

Configured for cookie and IP-based stickiness and TCP (HTTP and LDAP) load balancing. 

 

Instance Name 

LoadBalancer-8 

 

Port Number 

1389 

 

Pool Name 

DirectoryServer-UserData-Pool 

 

Virtual Server and Port Number 

LoadBalancer-8.siroe.com:1389 

 

Monitor 

LDAP-tcp 

Load Balancer 9 

Federation Manager Web Servers 

Virtual Service Address for the Federation Manager Web Server instances. 

SSL is terminated at this load balancer before the request is forwarded to the Access Manager servers.  

Configured for cookie and IP-based stickiness and TCP (HTTP and LDAP) load balancing. 

External users will access port 3443, while non-SSL port 1080 is used for proxying. 

 

Instance Name 

LoadBalancer-9 

 

Port Number 

1080 

 

Pool Name 

fm_server_pool 

 

Virtual Server and Port Number 

LoadBalancer-9.siroe.com:1080 

 

Monitor 

HTTP 

Load Balancer 10 

J2EE Policy Agents 

Virtual Service Address for J2EE Policy Agents 

SSL is terminated at this load balancer before the request is forwarded to J2EE Policy Agents. 

Configured for cookie and IP-based stickiness and TCP (HTTP and LDAP) load balancing. 

 

Instance Name 

LoadBalancer-10 

 

Port Number 

4080 

 

Pool Name 

federation_j2ee_agents 

 

Virtual Server and Port Number 

LoadBalancer-10.siroe.com:1080 

LoadBalancer-10.siroe.com:2443 

 

Monitor 

HTTP 

Load Balancer 11 

Web Policy Agents 

Virtual Service Address for Web Policy Agents. 

SSL is terminated at this load balancer before the request is forwarded to Web Policy Agents. 

Configured for cookie and IP— based stickiness and TCP (HTTP and LDAP) load balancing. 

 

Instance Name 

LoadBalancer-11 

 

Port Number 

5080 

 

Pool Name 

federation_web_agents 

 

Virtual Server and Port Number 

LoadBalancer-11.siroe.com:2080 

LoadBalancer-11.siroe.com:5443 

 

Monitor 

HTTP