LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Confused noobie problem

To: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Subject: Re: Confused noobie problem
From: "Ben M. Wall" <bmwall@xxxxxxxxx>
Date: Mon, 24 Nov 2003 17:47:42 -0500
> "Ben M. Wall" wrote:
> > 
> 
> please turn line wrap on. Your paratgraphs are on one line that goes off the 
> edge of my page

Im using vi in mutt right now so Ill try to wrap my lines.  Sorry.  I know how 
annoying
that can be.

> 
> actually it's much worse than you think. Very few people understant it all
> (including me) :-)
> 

I think you understand it just fine.  It is just that there are too many 
options, so
many ways of doing it.  That is a good thing, but it does make it harder to 
understand.

> >  Wow I have been using 2.4 kernels for a while now, its a wonder that I 
> > never ran into this before.  
> >  So it seems like this is really a firewalling issue.  It seems to me like 
> > I would want to be able to use netfilter for each virtual server 
> > seperately, and not just for the whole machine.  
> 
> hmm, read
> 
> http://www.linuxvirtualserver.org/Joseph.Mack/HOWTO/LVS-HOWTO.patches.html#firewall_on_director
>

Yeah, that is mostly what I meant.  I am not using LVS for my firewall, I just 
wanted to use
netfilter on this box to lock it down.  I shouldnt need to do that though, so I 
dont think
that I want to mess with this patch right now.  I think that Ill try the 
IProute2 way, just
because I think it is idealogically superior.  Wait, before I go trudging off 
into iproute2
land, let me ask this.  If I go the iproute2/keepalived route then will I be 
able to use
Netfilter without any kernel patches?  That is the whole idea right?  

> > Is iproute2 as easy to set up as the eth0:185 syntax?
> 
> no it's a nightmare, which is why people are still using the alias style of 
> setting up IPs
> 
> http://www.linuxvirtualserver.org/Joseph.Mack/HOWTO/LVS-HOWTO.policy_routing.html
>

Ahh..  Well, I like a good scary nightmare every now and again.  That is why I 
learned VI
after all!

Thanks again for all the advice and pointers, I would still be scratching my 
head if I 
didnt have help like this.  Maybe I can even contribute to this project in some 
way.  I
actually like writing documentation, maybe I could help out with that once I 
understand
it more.  Of course I would have to have you all look it over, but that is 
obvious.
 
Ben

> Joe
> 
<Prev in Thread] Current Thread [Next in Thread>