LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: firewall + loadbalancer on the same machine

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: firewall + loadbalancer on the same machine
From: Atif Ghaffar <aghaffar@xxxxxxxxxxxx>
Date: Tue, 03 Aug 2004 14:28:12 +0200
Hi Roberto,

Roberto Nibali wrote:

http://www.austintek.com/LVS/LVS-HOWTO/HOWTO/LVS-HOWTO.filter_rules.html

Is this clear enough or does it raise more questions? We would like to know so we can improve on the documentation.

Thanks for the link. I will read it and give you back my feedback.
For some reason, I did not see that page before. Or perhaps it is newer than I last read the docs. (~ 6 months ago, when we implemented lvs)


Out of the box it does not work, correct. But patches exist to make it work. You seem to have neglected to mention

a) your kernel version
b) your LVS forwarding method

We are using 2.4.22xx kernel from SuSE Linux 9.0 (Will change to RHEL 3 maybe)
The LVS Forwarding method is NAT




both points have different outcomes in answering your question to its full extent. 2 examples, randomly picked:

LVS-NAT with the nfct patch will work for 2.4.x and 2.6.x kernels regarding filtering, iif you don't use fwmark

Thanks. I will try that.

best regards

<Prev in Thread] Current Thread [Next in Thread>