Deployment Guide-Dell EMC ECS
Deployment Guide-Dell EMC ECS
Deployment Guide-Dell EMC ECS
Deployment Guide
Copyright Notices
Copyright © 2002-2018 KEMP Technologies, Inc. All rights reserved. KEMP Technologies and the KEMP
Technologies logo are registered trademarks of KEMP Technologies, Inc.
KEMP Technologies, Inc. reserves all ownership rights for the LoadMaster and KEMP 360 product line
including software and documentation.
Used, under license, U.S. Patent Nos. 6,473,802, 6,374,300, 8,392,563, 8,103,770, 7,831,712, 7,606,912,
7,346,695, 7,287,084 and 6,970,933
Table of Contents
1 Introduction 5
2 Template 6
5.1.1 S3 HTTP 10
5.1.3 S3 HTTPS 12
6 Troubleshooting 27
7 References 28
1 Introduction
The DELL EMC Elastic Cloud Storage (ECS) is a rack-based, flexible, and expandable object storage
solution. The ECS is configured through a Web Management Interface frontend (HTTPS). In combination
with a KEMP load balancer, an ECS can provide object storage using the protocols S3, Atmos, SWIFT, and
Network File System (NFS) in addition to the Web Management Interface. Other protocols such as CAS
are also possible but are published without load balancers.
This guide outlines the configuration of VSs based on best practices. When SSL/TLS offloading is not
required, Layer 4 is used to pass the traffic back to the ECS nodes. Transparency is automatically enabled
when using Layer 4. This sends the original source IP address to the Real Servers. For more information,
see the Transparency document on the KEMP Documentation page. Using Layer 4 has the following
requirements:
2 Template
KEMP has developed a template containing our recommended settings for this workload. You can install
this template to help when creating Virtual Services (VSs) because it automatically populates the settings.
This is quicker and easier than manually configuring each VS. If needed, changes can be made to any of
the VS settings after using the template.
Download released templates from the Templates section on the KEMP Documentation Page: .
For more information and steps on how to import and use templates, refer to the Virtual Services and
Templates, Feature Description on the KEMP Documentation Page.
The following table provides a list of the Dell EMC ECS default ports and protocols used for accessing the
storage.
In a one-armed setup (where the Virtual Service and Real Servers are on the same network/subnet)
Subnet Originating Requests is usually not needed. However, enabling Subnet Originating Requests
should not affect the routing in a one-armed setup.
In a two-armed setup where the Virtual Service is on network/subnet A, for example, and the Real
Servers are on network B, Subnet Originating Requests should be enabled on LoadMasters with
firmware version 7.1-16 and above.
When Subnet Originating Requests is enabled, the LoadMaster routes traffic so that the Real Server
sees traffic arriving from the LoadMaster interface that is in that network/subnet and not the Virtual
Service address.
When Subnet Originating Requests is enabled globally, it is automatically enabled on all Virtual Services.
If the Subnet Originating Requests option is disabled globally, you can choose whether or not to enable
Subnet Originating Requests on a per-Virtual Service basis.
1. In the main menu of the LoadMaster Web User Interface (WUI), go to System Configuration >
Miscellaneous Options > Network Options.
The table in each section outlines the settings configured by the application template. You can use this
information to manually configure Virtual Services or using KEMP LoadMaster Application Programming
Interface (API) and automation tools.
5.1.1 S3 HTTP
The following are the steps involved and the recommended settings to configure the S3 HTTP using the
application template:
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
This table outlines the configuration options set using the KEMP application template. These settings can
be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9020
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Scheduling Method Least Connection
Real Server Check Method TCP Connection Only
Checked Port 9020
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
6. Select the certificate to use in the Available Certificates and click the “arrow” > to move it to
Assigned Certificates.
This table outlines the configuration options set using the KEMP application template. These settings can
be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9021
VS Protocol tcp
Service Type Generic
Subnet Originating Address Enabled
Scheduling Method least connection
SSL Acceleration Enabled
TLS1.0, TLS1.1, TLS1.2 Enabled
Cipher Set Best Practices
Real Server Check Method TCP Connection Only
Checked Port 9020
5.1.3 S3 HTTPS
The following are the steps involved and the recommended settings to configure the S3 HTTPS using the
application template:
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
This table outlines the configuration options set using the KEMP application template. These settings
can be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9021
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Scheduling Method least connection
Real Server Check Method TCP Connection Only
Checked Port 9021
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
This table outlines the configuration options set using the KEMP application template. These settings
can be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9022
VS Protocol tcp
Option Value
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
6. Select the certificate to use in the Available Certificates and click the “arrow” > to move it to
Assigned Certificates.
This table outlines the configuration options set using the KEMP application template. These settings
can be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9023
VS Protocol tcp
Service Type Generic
Subnet Originating Address Enabled
Scheduling Method least connection
SSL Acceleration Enabled
TLS1.0, TLS1.1, TLS1.2 Enabled
Cipher Set Best Practices
Real Server Check Method TCP Connection Only
Checked Port 9022
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
This table outlines the configuration options set using the KEMP application template. These setting can
be used if doing a manual configuration or leveraged with scripts and automation tools
Option Value
VS Port 9023
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Scheduling Method Least Connection
Real Server Check Method TCP Connection Only
Checked Port 9023
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
This table outlines the configuration options set using the KEMP application template. These settings
can be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9024
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Scheduling Method least connection
Real Server Check Method TCP Connection Only
Checked Port 9024
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
6. Select the certificate to use in the Available Certificates and click the “arrow” > to move it to
Assigned Certificates.
This table outlines the configuration options set using the KEMP application template. These settings
can be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9025
VS Protocol tcp
Service Type Generic
Subnet Originating Address Enabled
Scheduling Method least connection
SSL Acceleration Enabled
TLS1.0, TLS1.1, TLS1.2 Enabled
Cipher Set Best Practices
Real Server Check Method TCP Connection Only
Checked Port 9024
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
This table outlines the configuration options set using the KEMP application template. These settings can
be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 9025
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Scheduling Method least connection
Checked Port 9025
1. In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
3. Select the ECS Web Interface template in the Use Template drop-down list.
5. Click View/Modify Services and select the ECS Web Interface HTTPS Re-encrypted Virtual
Service on port 443.
7. Select the certificate to use in the Available Certificates and click the “arrow” > to move it to
Assigned Certificates.
This table outlines the configuration options set using the KEMP application template. These settings can
be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 443
VS Protocol tcp
Service Type HTTP-HTTP/2-HTTPS
Subnet Originating Address Enabled
Scheduling Method Least Connection
SSL Acceleration Enabled
SSL Reencrypt Enabled
TLS1.0, TLS1.1, TLS1.2 Enabled
Cipher Set Best Practices
Real Server Check Method HTTPS Protocol
1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add
New.
This table outlines the configuration options set using the KEMP application template. These settings can
be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 111
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Persistence Mode Source IP Address
Timeout 1 Day
Scheduling Method least connection
Real Server Check Method TCP Connection Only
Checked Port 111
1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add
New.
3. Select the NFS Mountd template in the Use Template drop-down list.
This table outlines the configuration options set using the KEMP application template. These settings can
be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 2049
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Persistence Mode Source IP Address
Timeout 1 Day
Scheduling Method least connection
Real Server Check Method TCP Connection Only
Checked Port 2049
1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New.
This table outlines the configuration options set using the KEMP application template. These settings can
be used if doing a manual configuration or leveraged with scripts and automation tools.
Option Value
VS Port 10000
VS Protocol tcp
Service Type Generic
Force L4 Enabled
Persistence Mode Source IP Address
Persistence Timeout 1 Day
Scheduling Method least connection
Real Server Check Method TCP Connection Only
Checked Port 10000
6 Troubleshooting
Refer to the sections below for details on some common issues seen when load balancing the Dell EMC
ECS workload.
7 References
Some resources on Dell EMC ECS are listed below: