LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: LinuxVirtualServer as firewall

To: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Subject: Re: LinuxVirtualServer as firewall
From: Josep Llaurado Selvas <darlock@xxxxxxxxx>
Date: 27 Mar 2002 12:38:10 +0100
Hello,

Adding the route to local I loose the connection to the firewall. 

I have seen when I connect to LVS www port (both firewalls have squid
transparent-proxy installed and caching the www connections), the LVS
runs well, getting a round-robin connection between the two firewalls.
It seems the 'route suggestion' of Julian it's ok, but the solution
locks the firewall. 

Anybody can help me about setting the 'ip route' commands to allow the
outbond connections throw the LVS-Firewall runs ok? 
Or anybody can point me out to any doc about setting the advanced Linux
routing capabilities? I'm not an expertise and I need some help...

TIA.

On Mon, 2002-03-25 at 22:55, Julian Anastasov wrote:
> 
>       Hello,
> 
> On 25 Mar 2002, Josep Llaurado Selvas wrote:
> 
> > #
> > # Enabling eth0:30
> > #
> > /sbin/ifconfig eth0:30 192.168.1.30 broadcast lvs netmask
> > 255.255.255.255
> > /sbin/route add -host 192.168.1.30 dev eth0:30
> 
>       Do you have:
> 
> ip rule from 192.168.1.0/24 table 100
> ip route add local 0/0 dev lo table 100
> 
>       and of course, with the right priority according to all routes?
> 
> > TIA.
> 
> Regards
> 
> --
> Julian Anastasov <ja@xxxxxx>
> 
> 
> _______________________________________________
> LinuxVirtualServer.org mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
> Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
> or go to http://www.in-addr.de/mailman/listinfo/lvs-users
-- 
_________________________________________________________
Josep Llauradó Selvas                   darlock@xxxxxxxxx
              Linux Registered User #153481
The only "intuitive" interface is the nipple.
After that, it's all learned.
(in comp.os.linux.misc, on X interfaces.)
_________________________________________________________

Attachment: signature.asc
Description: This is a digitally signed message part

<Prev in Thread] Current Thread [Next in Thread>