> "Ben M. Wall" wrote:
> >
>
> please turn line wrap on. Your paratgraphs are on one line that goes off the
> edge of my page
Im using vi in mutt right now so Ill try to wrap my lines. Sorry. I know how
annoying
that can be.
>
> actually it's much worse than you think. Very few people understant it all
> (including me) :-)
>
I think you understand it just fine. It is just that there are too many
options, so
many ways of doing it. That is a good thing, but it does make it harder to
understand.
> > Wow I have been using 2.4 kernels for a while now, its a wonder that I
> > never ran into this before.
> > So it seems like this is really a firewalling issue. It seems to me like
> > I would want to be able to use netfilter for each virtual server
> > seperately, and not just for the whole machine.
>
> hmm, read
>
> http://www.linuxvirtualserver.org/Joseph.Mack/HOWTO/LVS-HOWTO.patches.html#firewall_on_director
>
Yeah, that is mostly what I meant. I am not using LVS for my firewall, I just
wanted to use
netfilter on this box to lock it down. I shouldnt need to do that though, so I
dont think
that I want to mess with this patch right now. I think that Ill try the
IProute2 way, just
because I think it is idealogically superior. Wait, before I go trudging off
into iproute2
land, let me ask this. If I go the iproute2/keepalived route then will I be
able to use
Netfilter without any kernel patches? That is the whole idea right?
> > Is iproute2 as easy to set up as the eth0:185 syntax?
>
> no it's a nightmare, which is why people are still using the alias style of
> setting up IPs
>
> http://www.linuxvirtualserver.org/Joseph.Mack/HOWTO/LVS-HOWTO.policy_routing.html
>
Ahh.. Well, I like a good scary nightmare every now and again. That is why I
learned VI
after all!
Thanks again for all the advice and pointers, I would still be scratching my
head if I
didnt have help like this. Maybe I can even contribute to this project in some
way. I
actually like writing documentation, maybe I could help out with that once I
understand
it more. Of course I would have to have you all look it over, but that is
obvious.
Ben
> Joe
>
|