Viperman wrote:
>
> Thanks, Joe.
>
> I think I got it now.
> So in fact there is a way for my provider to allow the spoofing for me and
> not only to all clients like they said.
the only extra thing they have to do it to allow packets from your
realservers with src_addr=VIP:port (where VIP:port is the LVS'ed service).
Their problem is that they don't own the network containing the VIP,
and they normally wouldn't have packets with src_addr=VIP coming
from any of their machines. They can block packets with
src_addr=VIP:all_other_ports.
Joe
--
Joseph Mack PhD, High Performance Computing & Scientific Visualization
SAIC, Supporting the EPA Research Triangle Park, NC 919-541-0007
Federal Contact - John B. Smith 919-541-1087 - smith.johnb@xxxxxxx
|