Horms wrote:
>
> The only slight difference
> is that LVS requires traffic for the VIP to be local, which usually
> means that it needs to be bound to a local interface. Any local
> interface.
>
> Actually you can get around this
this being "needing a local interface"?
> by moving ip_vs_in from the LOCAL_IN
> hook to the PREROUTING hook. I tried that briefly once and it seemed to
> work. But it most likely has some interesting side effects.
would it solve the problem of not having the VIP on the director,
ie when accepting packets for LVS by transparent proxy or fwmark?
Joe
--
Joseph Mack PhD, High Performance Computing & Scientific Visualization
SAIC, Supporting the EPA Research Triangle Park, NC 919-541-0007
Federal Contact - John B. Smith 919-541-1087 - smith.johnb@xxxxxxx
|