LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: LVS NAT with VPN

To: Mark Weaver <mark@xxxxxxxxxx>
Subject: Re: LVS NAT with VPN
Cc: LVS Users <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
From: Julian Anastasov <ja@xxxxxx>
Date: Fri, 15 Feb 2002 12:09:47 +0200 (EET)
        Hello,

On Fri, 15 Feb 2002, Mark Weaver wrote:

> Hi,
>
> I've got a network with the following (slightly strained, and simplified)
> configuration:
>
>       remote network, 10.0.5.0/24
>               |
>               | IPSEC tunnel
>               |
>       router, firewall, LVS 192.168.1.1, subnet 192.168.1.0/24
>               |
>               |
>               |
>         real server 192.168.1.7
>
> Now my problem is that connections from the remote network to load balanced
> ports on the VPN fail in a very weird way.  Things that work are:
>
> - telnet to 192.168.1.7 from inside the 192.168.1.0/24 network on any port
> - telnet to 192.168.1.7 from the remote network on any port OTHER than the
> load balanced ports
>
> It all goes pear-shaped when you try to connect from the IPSEC machine
> though.  Now I don't know enough about how LVS+NAT works internally to

        You have to show us the following settings:

- kernel and LVS version in director

- ipvsadm rules

- routes and firewall rules used to keep the IPSec tunnel

> Thanks in advance,
>
> Mark

Regards

--
Julian Anastasov <ja@xxxxxx>



<Prev in Thread] Current Thread [Next in Thread>