LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: LVS-TUN setup - responses from realserver not being let through

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: LVS-TUN setup - responses from realserver not being let through
From: Joseph Mack NA3T <jmack@xxxxxxxx>
Date: Mon, 18 Sep 2006 11:11:48 -0700 (PDT)
On Mon, 18 Sep 2006, Per Jessen wrote:

OK, just a quick feedback - the datacenter has confirmed they've got a
router check for "IP Spoofing" enabled, which prevents the real server
responses from getting through.  I've now ordered 5 servers on the same
physical network, which will then hopefully work.  If not, I guess I
could resort to LVS-NAT.

the problem is not the RIPs on the realservers, which can be anything (presumably belonging to the datacenter's IP range), but the packets with src_addr=VIP going to 0/0. The datacenter doesn't have the VIP in its range, it's in your range, but it's coming out of the machines in their datacenter.

Joe

--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!

<Prev in Thread] Current Thread [Next in Thread>