LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Re-routing packets back through the tunnel

To: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Subject: Re: Re-routing packets back through the tunnel
From: Malcolm Turnbull <Malcolm.Turnbull@xxxxxxxxxxxx>
Date: Wed, 16 Oct 2002 16:06:29 +0100
You could change the firewall 1 config so that it doesn't use statefull inspection on port 80 for those IP addresses.

i.e. Just open the port and be done with it.

Don't know how you do this though... :-).

Ditching the FW1 for iptables may been seen as a drastic solution.



laurie.baker@xxxxxx wrote:
Hi All,
We have a trial system running LVS/TUN, (loadbalancer feeding 2 x Webservers
(down the tunnels) talking to two tomcat servers back-ended with 2 x MySQL
dB's,

Initially the LVS / TUN was configured in the conventional way with the
loadbalancer doing the client -> server process and the return traffic to
the client going directly out from the side of the webservers to the client.

Now ! this configuration ran into problems as our hosting firewall
(Checkpoint FW1) was throwing away the return packets to the clients as if
it had no concept of where these packets came from (I think this was because
the MAC was different to that of the loadbalancer (virtual server) I'm not
sure on that sorry). Anyway, to resolve the issue the developers configured
the webservers to have a default route of the loadbalancer, therefore
squirting the return traffic back through the tunnel !

Well! I have not seen this style of configuration for LVS / TUN (yes this is
correct for LVS / NAT) but it worked at the time, however I am now seeing
queues (and often stalling of the service) as the webserver -> tomcat
bottlenecks.

I would love some constructive comments on the above information (anything
that would point to the best resolution to this problem).
regards
Laurie

_______________________________________________
LinuxVirtualServer.org mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
or go to http://www.in-addr.de/mailman/listinfo/lvs-users

--
Regards,

Malcolm Turnbull
IT Manager

Crocus.co.uk Ltd
01344 629661
07715 770523




<Prev in Thread] Current Thread [Next in Thread>