In reply to question From: David [mailto:dh@xxxxxxxxx]
Sent: 12 December 2002 10:44
>>I think it would be best for us to setup a LVS-DR or LVS-TUN.
I'm sure someone else can comment better but, TUN fits in with your design
(R(eal)S(erver) routing back to firewall and not through director) But
BEWARE some firewalls (some versions of Checkpoint FW1) will reject the
return traffic if the packet passed back is not seen to originate from the
director (to which the firewall first passed it!)
I hope that makes sense? With DR this should not be a problem as the
traffic is routed via the director in both directions.
Someone correct me if I'm wrong.
>>how it is passed back to the client does not matter.
Depending on how your firewall handles this it does!
>>I am just a bit confused by the mentioning of the RIP and VIP in the
documentation.
This may refer to the above?
I hope this helps.
Laurie.
|