LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Direct/Tunneling lvs and spoofing protection

To: Joseph Mack <mack@xxxxxxxxxxx>
Subject: Re: Direct/Tunneling lvs and spoofing protection
Cc: Stephen Zander <gibreel@xxxxxxxxx>, lvs-users@xxxxxxxxxxxxxxxxxxxxxx
From: Stephen Zander <gibreel@xxxxxxxxx>
Date: 14 Mar 2000 09:07:11 -0800
>>>>> "Joseph" == Joseph Mack <mack@xxxxxxxxxxx> writes:
    Joseph> in VS-DR and VS-Tun the packets returning fromthe
    Joseph> realservers to the client go directly to the client, via
    Joseph> the realservers default gw and _do_not_ go via the
    Joseph> director. With VS-NAT the packets go back through the
    Joseph> director.

In my configuration, the redirector is the default gateway.

The implication of that statement is that I must seperate my
redirection and firewall systems to make lvs work with VS-DR or
VS-Tun.  That's disappointing.

I was looking to VS-DR or VS-Tun to lover the round trip overhead by
minimising the kernel involvement on the outbound packets.  Guess
that's not possible.

-- 
Stephen

"Farcical aquatic ceremonies are no basis for a system of government!"


<Prev in Thread] Current Thread [Next in Thread>