LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: [lvs-users] solved: last FIN-ACK eaten (by iptables)

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: [lvs-users] solved: last FIN-ACK eaten (by iptables)
From: Brian Ghidinelli <brian@xxxxxxxxx>
Date: Thu, 11 Sep 2008 19:59:44 -0700
Laurentiu C. Badea (L.C.) wrote:
> I have seen a few patches in the archives related to netfilter and LVS 
> but I preferred to use stock parts for ease of maintenance and reduced 
> probability of accidental wreck. Hopefully some of those will make it 
> into mainstream.

A blanket ACCEPT rule on outgoing traffic doesn't seem very secure for a 
firewall, though.

I'm surprised more people don't want to do stateful LVS... I guess once 
you get to a cluster, people have enough hardware to dedicate the LVS 
duties to some boxes?  It still seems like a valuable combination of tools.


Brian


<Prev in Thread] Current Thread [Next in Thread>