Julian Anastasov wrote:
>
>
> If you don't create any other outgoing masquerading connections
> from the internal servers you can just delete the ipchains rule. The LVS
> will maintain its connections without the help from ipchains. Even for
> the related ICMP messages. Use ipchains rules only for filtering in this
> case.
in 2.4.x VS-NAT, are all ports from the real-server masqueraded or only
the ports for the services that LVS is controlling?
Joe
--
Joseph Mack PhD, Senior Systems Engineer, Lockheed Martin
contractor to the National Environmental Supercomputer Center,
mailto:mack.joseph@xxxxxxx ph# 919-541-0007, RTP, NC, USA
|