LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Direct/Tunneling lvs and spoofing protection

To: Julian Anastasov <uli@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: Direct/Tunneling lvs and spoofing protection
Cc: Stephen Zander <gibreel@xxxxxxxxx>, lvs-users@xxxxxxxxxxxxxxxxxxxxxx
From: Joseph Mack <mack@xxxxxxxxxxx>
Date: Tue, 14 Mar 2000 21:13:24 -0500 (EST)
On Tue, 14 Mar 2000, Julian Anastasov wrote:

>       Yep, in VS/NAT mode you use the Director as default
> gateway for the real servers but for VS/DR and VS/TUN methods you
> have to use transparent proxy in the Director to receive packets
> for the VIPs. By this way if the Director thinks the VIP is not local,
> the outgoing packets will be successfully forwarded to the client.
> If the VIP is configured using ifconfig these packets are dropped
> from the source address validation code in the Director.

Hi Julian,

        So you can setup a VS-DR director with REDIRECT to handle
packets sent to the VIP? (sound of my brain popping). How does the
router know where to send packets with dst-addr=VIP?

Joe

--
Joseph Mack mack@xxxxxxxxxxx



<Prev in Thread] Current Thread [Next in Thread>