Julian Anastasov wrote:
> So, we need a way to nat the outgoing packets in the real
> server but only when we access the client's authd.
The packets from the real-server to the client's authd
come from the VIP on the real-server and not the RIP.
We fiddle with packets on the real-server
that come from VIP with ports 1025:65535.
> There is no
> route by fwmark for locally generated packet in 2.2, so I'm not
> sure how we will distinguish port 113 from port 1024 (the client).
Joe
--
Joseph Mack PhD, Senior Systems Engineer, Lockheed Martin
contractor to the National Environmental Supercomputer Center,
mailto:mack.joseph@xxxxxxx ph# 919-541-0007, RTP, NC, USA
|