David,
Why not get the firewall to NAT incoming traffic ?
i.e Firewall has public ip on outside and NATs your LVS VIP to another
public IP.
Then you are left with : (I cant do ascii art either)
Public Net
|
Firewall
|
Private Net (switch that ALL servers including the LVS are connected to
LVS with VIP (virtual IP that is redirected in turn to each RIP real Ip
on web servers)
The LVS will also need a RIP (management ip address) BUT on the same NIC
(you only need one network card)
Then each real server needs a RIP (its default ip address) and the SAME
VIP as the one on the LVS but on the loopback adapter.
Follow the example for DR in the FAQ.
Regards,
Malcolm Turnbull.
Crocus.co.uk Ltd
01344 629629
http://www.crocus.co.uk/
|