Re: [lvs-users] IPVS stops tunneling with ipip on SSL traffic causing se

To: Julian Anastasov <ja@xxxxxx>
Subject: Re: [lvs-users] IPVS stops tunneling with ipip on SSL traffic causing session failures
Cc: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
From: Phillip Moore <pdm@xxxxxxxxx>
Date: Fri, 28 Aug 2015 15:16:37 -0500
Thank you for the suggestion.

We didn't have the netfilter module loaded at all so I don't think it
would have having any impact. However I loaded it and set this setting
and it didn't change the behavior.
The ip_conntrack_tcp_be_liberal setting wasn't available on our kernel
version looks like I can't find a module to load to enable that.

We did find something interesting. If we add additional headers to the
working http request we can make it fail.

WORKS: curl -H "X:1"
FAILS:  curl -H "X:12"

190 bytes works, 191 bytes fails with the failure to tunnel problem.

Phillip Moore

On Fri, Aug 28, 2015 at 2:42 PM, Julian Anastasov <ja@xxxxxx> wrote:

>         Can you test with enabled nf_conntrack_tcp_be_liberal
> or ip_conntrack_tcp_be_liberal sysctl value in director?
> May be packets are dropped by conntrack because packets
> from reply direction are not seen.

Please read the documentation before posting - it's available at: mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
or go to

<Prev in Thread] Current Thread [Next in Thread>