LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: LVS-NAT + 2.4 iptables firewalling

To: lvs-users@xxxxxxxxxxxxxxxxxxxxxx, bench@xxxxxxxxxx
Subject: Re: LVS-NAT + 2.4 iptables firewalling
From: Joseph Mack <mack.joseph@xxxxxxx>
Date: Thu, 20 Jun 2002 18:50:11 -0400
Ben wrote:
> 
> Don't bother - it's already in the HOWTO. (Which, BTW, was one of the things
> that made the HOWTO hard to read - it had a lot of duplicated info stated in
> slightly different ways by many different people.)

Yes, the HOWTO could do with a good editing. 
However in areas that I don't know about, and have no easy way or time to
test/check the info, I just put in all the postings on the matter and hope
that people can sort it out from there. People occassionally send in sections
for the HOWTO for things they've sorted out and I'm happy to put them in.
In the meantime about 25% of the HOWTO is stuff I've checked myself and the
rest is just the sanest looking postings available on the matter. 
 
A section on writing filter rules would be a good idea. If you get 
something/anything out of your experience, could you write it down as you
go, and send it in for the HOWTO?

> The link you mention seems to imply that the lvs code hooks in somewhere
> around filterINPUT for packets coming into the LVS and somewhere around
> filterFORWARD for packets leaving the LVS. I think. Do  you agree?

As you can tell I don't know. This sounds a good place to start.
I've just added filter rules for 3-Tier realservers (mentioned now in the
HOWTO, and the new configure script is in the works but not out yet). I got
them to work by starting somewhere (eg questions on this mailing list)
and using the monkey/typewriter/sonnet principle guided by the 
logs and more questions to people here, to work my way through it. 

Joe
--
Joseph Mack PhD, Senior Systems Engineer, Lockheed Martin
contractor to the National Environmental Supercomputer Center, 
mailto:mack.joseph@xxxxxxx ph# 919-541-0007, RTP, NC, USA


<Prev in Thread] Current Thread [Next in Thread>