Hello,
If I use something like that:
[Internet]
|
|
[LVS Box]
|
+--------+-------+
| |
[Firewall 1] [Firewall 2]
| |
+--------+-------+
|
|
[LAN]
As I understand, the SH scheduler let's you be
sure that a connexion coming from the LAN and
going through Firewall 2 will get the LVS-Box to
redirect all receiving packets for that connection
to Firewall 2.
What's wrong in having the returned packets to
go trough Firewall 1, TCP/IP allows differents routes
for the packets, and in both case the client will
receive the packet (simply not from the same
Firewall).
Thanks,
Fabrice Bucher
|