LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: [lvs-users] IPVS stops tunneling with ipip on SSL traffic causing se

To: Phillip Moore <pdm@xxxxxxxxx>
Subject: Re: [lvs-users] IPVS stops tunneling with ipip on SSL traffic causing session failures
Cc: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
From: Julian Anastasov <ja@xxxxxx>
Date: Fri, 28 Aug 2015 22:42:43 +0300 (EEST)
        Hello,

On Fri, 28 Aug 2015, Phillip Moore wrote:

> I do not understand why on line 15 of the tcpdump you can see a 326
> byte packet is received from the client, but isn't forwarded to the
> real server. There wouldn't be any fragmentation issues with that
> would there? On line 15 you can see it keeps receiving the same packet
> 6 times and fails to forward it on.

        Can you test with enabled nf_conntrack_tcp_be_liberal
or ip_conntrack_tcp_be_liberal sysctl value in director?
May be packets are dropped by conntrack because packets
from reply direction are not seen.

Regards

--
Julian Anastasov <ja@xxxxxx>

_______________________________________________
Please read the documentation before posting - it's available at:
http://www.linuxvirtualserver.org/

LinuxVirtualServer.org mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
or go to http://lists.graemef.net/mailman/listinfo/lvs-users

<Prev in Thread] Current Thread [Next in Thread>