LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: IVPS and IPTABLE conntrack

To: Hervé Guehl <guehlh@xxxxxxxxxxxx>
Subject: Re: IVPS and IPTABLE conntrack
Cc: <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
From: Julian Anastasov <ja@xxxxxx>
Date: Wed, 26 Sep 2001 22:20:12 +0000 (GMT)
        Hello,

On Wed, 26 Sep 2001, Hervé Guehl wrote:

> Hi,
> I had a problem with ipvs and iptables (ipvs 0.8.1) (iptables 1.2.2 kernel 
> 2.4.7).
>
> My configuration was the following :
>
>     vip1 -> Rserver 1
>     vip2 -> Rserver 1
>     vip3 -> Rsever 2
>     vip4 -> rserver 4
>
> I did this cos I had another machine in from that was doing some source 
> routing (different def gw depending of vip)..
>
> The problem was... At one moment the ipvs stopped working (real server where 
> no more reachable)...

        We don't believe in magic. Also, we don't have tools to sniff
your network for problems. Please, provide some tcpdump outputs. The
LVS-HOWTO is a good source for ideas.

> I was using some firewall rules on the machine...

        You can try without firewall rules first, try to investigate
where is the problem.

> But I have a question : why IPVS and IPTABLES conn_track are not merged ??

        There are more reasons against this merge. You can find them in:

- more forwarding methods
- QoS
- more methods for local delivery
- etc

        You can assume that the new Netfilter model is not perfect for
everything, LVS is one of these things.


> Thx.
>
> Hervé


Regards

--
Julian Anastasov <ja@xxxxxx>



<Prev in Thread] Current Thread [Next in Thread>