On Fri, Apr 23, 2004 at 09:15:24AM +0200, Michael Daum wrote:
> On Thursday 22 April 2004 17:41, Joseph Mack wrote:
> > Michael Daum wrote:
> > >
> > > But I had to switch on SNAT
> > > also to get all services work properly from the realservers. Is that
> > > meant to
> > > be so?
> >
> > No.
> >
> > ip_vs has NAT in both directions already built in.
> > The reply packets come out already NAT'ed for you
>
> What about packages that originate from the realservers, e.g. dns.
> The ip_vs is not expecting these packages and will not NAT these.
> iptables' SNAT will happily fill that gap.
Yes.
--
Horms
|