Managing Your Network : Managing Appliances : Managing Appliance Pages : Managing Subnet Side Rules
  
Managing Subnet Side Rules
You configure subnet side rules in the Editing Appliance Configuration: <hostname>, Subnet Side Rules page.
You need to configure subnet side rules to support VSP and Flow Export on a virtual in-path deployment.
Subnet side rules enable you to configure subnets as LAN-side subnets or WAN-side subnets for a virtual in-path SteelHead appliance. The subnet side rules determine whether traffic originated from the LAN or the WAN-side of the SteelHead appliance based on the source subnet. You must configure subnets on each SteelHead appliance in a virtual in-path configuration, as the subnets for each will likely be unique.
With subnet side rules in place, RiOS can send incoming packets to the correct VSP VNIs for VVSP, and, a virtual in-path SteelHead can use flow export collectors such as NetFlow to analyze nonoptimized or passed through traffic correctly. Otherwise, the SteelHead appliance cannot discern whether the traffic is traveling from the LAN to the WAN or in the opposite direction. This can result in over-reporting traffic in a particular direction or for a particular interface.
Note: FakeIndex is necessary for correct optimized traffic reporting. For details, see the Riverbed Deployment Guide.
Tip: You cannot delete the default rule, Default, which optimizes all remaining WAN-side traffic that has not been selected by another rule. This rule is always listed last.
This page applies to SteelHead and SteelHead EX.
To configure subnet side rules settings
1. Choose Manage > Topology: Appliances to display the Appliances page.
2. Select the name of the appliance you want to edit to expand the page and display the Appliance tabs.
3. Select the Appliance Pages tab to display the Appliance Configuration Pages list.
4. Under Appliance Configuration Pages, click Subnet Side Rules to display the Editing Appliance Configuration: <hostname>, Subnet Side Rules page.
Figure: Editing the Subnet Side Rules
5. Complete the configuration as described in this table.
Control
Description
Add a Subnet Side Rule
Displays the controls to create a subnet side rule.
Insert Rule At
Select Start, End, or a rule number from the drop-down list.
SteelHead appliances evaluate rules in numerical order starting with rule 1. If the conditions set in the rule match, then the rule is applied, and the system moves on to the next packet. If the conditions set in the rule do not match, the system consults the next rule. For example, if the conditions of rule 1 do not match, rule 2 is consulted. If rule 2 matches the conditions, it is applied, and no further rules are consulted.
Subnet
Specify the subnet. Use this format:
<ip-address>/<subnet-mask>
Subnet is on the LAN side of this appliance
In virtual in-path configurations, all traffic is flowing in and out of one physical interface. Select to specify that the subnet is on the LAN side of the device.
Subnet is on the WAN side of this appliance
In virtual in-path configurations, all traffic is flowing in and out of one physical interface. Select to specify that the subnet is on the WAN side of the device.
Add
Adds the rule to the subnet map table. The Management Console redisplays the subnet map table and applies your changes to the running configuration, which is stored in memory.
Remove Subnet Rules
Select the check box next to the name and click Remove Subnet Rules.