Juergen Jaeschke wrote:
>
> Hi,
>
> if I try to direct services to another port
> (say incoming is VIP:180, this is fw-marked to 0xb, and i've
> set up a rule to DR packets with 0xb to RIP:80)
how did you setup this rule? You can only change ports with VS-NAT.
With VS-DR you cannot rewrite the port.
> then i end
> up in packets to the RIP:VPORT, that is RIP:180 instead
> of RIP:80.
>
> I tried to DNAT this service to port 80,
I don't know who gets the packets first, LVS or DNAT.
Assuming you get it to work, the behaviour you'll get
is probably not part of the LVS spec and it may not
work in the future. LVS has an uneasy coexistance
with netfilter.
Joe
--
Joseph Mack PhD, Senior Systems Engineer, Lockheed Martin
contractor to the National Environmental Supercomputer Center,
mailto:mack.joseph@xxxxxxx ph# 919-541-0007, RTP, NC, USA
|