LVS-TUN headaches

To: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Subject: LVS-TUN headaches
From: "khiz nms" <khiznms@xxxxxxxxxxxxxx>
Date: 31 Dec 2001 08:54:41 -0000
Hi all
i m facing a problem with my TUN setup

my real server is on a seperate network from the director and is not prone to 
the ARP problem coz there is no routing for the VIP which leads to the 
realserver's network!!
 realserver is redhat 6.2 VIP

ipvsadm is correctly configured for tunnelling to the RIP and this i have 
verified by using tcpdump on the Realserver and i see packets CIP->RIP hitting 
the realserver

tcpdump on realserver
 eth2 < > S 421444096:42144409 6(0) win 
65535 <mss 1460> (DF) (ipip) 
where is CIP

the director has only one NIC configured with VIP
result of ipvsadm

IP Virtual Server version 1.0.8 (size=32768)
Prot LocalAddress:Port Scheduler Flags
 -> RemoteAddress:Port Forward Weight ctiveConn InActConn
TCP rr
  ->     Tunnel  4      0          2     

However connections from the client seem to hang

IP spoofing is enabled on the routers because doing 
traceroute -n -s VIP someother IP from the REALSERVER
 result in icmp port unreachable messages occuring on the Director which only 
arps for the VIP.. this impies that spoofing of VIP from REALSERVER is permitted

i have configured VIP on tunl0 

telnet VIP www  from realserver itself is also successful

ifconfig on REALSERVER gives
eth2  blah blah
tunl0     Link encap:IPIP Tunnel  HWaddr
          inet addr:  Mask:
          UP RUNNING NOARP  MTU:1480  Metric:1

route -n shows UH    0      0        0 tunl0 UH    0      0        0 eth2   U     0      0        0 eth2       U     0      0        0 lo         UG    0      0        0 eth2 VIP

a route to the VIP exists with dev tunl0 ( only one VIP in use on the 

ip forwarding enabled on realserver 
lsmod shows ipip ;-)
i dunno whats wrong with the configuration
pls help me out
BTW realserver is 6.2 redhat  2.2.14-5.0  ipip is a module

P>S the only commands i used on the director
ipvsadm -A -t -s wlc
ipvsadm -a -t -r -i

i did not use any configure script .. this seems fine coz the director is 
actaully passing tunnelled packets to the Realserver..hope i m right 


<Prev in Thread] Current Thread [Next in Thread>
  • LVS-TUN headaches, khiz nms <=