LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: using arptables to block ARP

To: simpsonb@xxxxxxxxxxxxxxxxxxxxxx, <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: using arptables to block ARP
From: Joseph Mack <mack.joseph@xxxxxxx>
Date: Fri, 18 Jun 2004 13:39:27 -0400
Brett Simpson wrote:

> > you can also use arp filtering, although no-one seems to be doing it

so you're doing it, these are your settings (IPADDR==VIP on the realserver?),
it's working and you're happy with it?

Joe

> With Redhat WS?/ES/AS 3.0 with the latest kernel update includes Julians
> ARP ignore patch.
> 
> /etc/sysctl.conf
> net.ipv4.conf.lo.arp_ignore = 1
> net.ipv4.conf.lo.arp_announce = 2
> net.ipv4.conf.all.arp_ignore = 1
> net.ipv4.conf.all.arp_announce = 2
> 
> /etc/sysconfig/network-scripts/ifcfg-lo:1
> DEVICE=lo:1
> IPADDR=192.168.0.57
> NETMASK=255.255.255.255
> NETWORK=192.168.0.0
> ONBOOT=yes
> ARP=no
> 
> _______________________________________________
> LinuxVirtualServer.org mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
> Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
> or go to http://www.in-addr.de/mailman/listinfo/lvs-users

-- 
Joseph Mack PhD, High Performance Computing & Scientific Visualization
SAIC, Supporting the EPA Research Triangle Park, NC 919-541-0007
Federal Contact - John B. Smith 919-541-1087 - smith.johnb@xxxxxxx
<Prev in Thread] Current Thread [Next in Thread>