Sorry for the double post, but I feel I should clarify that the ipchains is
stricter than when I had that loop from before. (I had everything to
"ACCEPT" temporarily instead of my standard "DENY"). If you would like I
can of course change this back.
> > 1. tcpdump -len host 64.211.248.11
>
> This is one request for the VIP
> {{{{ From real server #1, only server in loop currently to
> simplify analysis
> }}}}
> [root@fe4026 fea]# /usr/sbin/tcpdump -len host 64.211.248.11
> Kernel filter, protocol ALL, datagram packet socket
> tcpdump: listening on all devices
> 10:33:11.341911 eth1 < 0:d0:b7:a9:c1:bc 0:0:0:0:0:1 ip 62:
> 208.177.165.227.64395 > 64.211.248.11.www: S
> 2833366593:2833366593(0) win
> 16384 <mss 1460,nop,nop,sackOK> (DF)
> 10:33:14.236010 eth1 < 0:d0:b7:a9:c1:bc 0:0:0:0:0:1 ip 62:
> 208.177.165.227.64395 > 64.211.248.11.www: S
> 2833366593:2833366593(0) win
> 16384 <mss 1460,nop,nop,sackOK> (DF)
> 10:33:20.246000 eth1 < 0:d0:b7:a9:c1:bc 0:0:0:0:0:1 ip 62:
> 208.177.165.227.64395 > 64.211.248.11.www: S
> 2833366593:2833366593(0) win
> 16384 <mss 1460,nop,nop,sackOK> (DF)
|