LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: LVS NAT packets not beein de-masquaraded

To: Mack.Joseph@xxxxxxxxxxxxxxx
Subject: Re: LVS NAT packets not beein de-masquaraded
Cc: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Cc: wensong@xxxxxxxxxxxx
From: Horms <horms@xxxxxxxxxxxx>
Date: Fri, 4 Mar 2005 13:56:53 +0900
Hi Joe,

this definately is a problem that needs to be investigated.
I don't have time right now as I am on holidays, but hopefully
I will get a chance to look into it in the next week or so.
But perhaps Wensong or Julian will get to it first.

On Thu, Mar 03, 2005 at 12:13:40PM -0500, Mack.Joseph@xxxxxxxxxxxxxxx wrote:
> Joseph Mack PhD, High Performance Computing & Scientific Visualisation
> LMIT, Supporting the EPA Research Triangle Park, NC 919-541-0007
> Federal Contact - John B. Smith 919-541-1087 - smith.john@xxxxxxx
> 
> lvs-users-bounces@xxxxxxxxxxxxxxxxxxxxxx wrote on 03/03/2005 12:00:46
> PM:
> 
> >
> > Hi,
> >
> > We have a problem with 6 webservers behind an ipvs node
> > using wlc & nat.
> >
> > We're seeing SYN packets come in, beeing forwarded to the webserver,
> > seeing the webserver send a SYN/ACK back to the ipvs node,
> > and than from
> > the lvs node back to the client WITHOUT the src address rewritten.
> 
> a few people have reported similar problems with LVS-NAT.
> It's not happening with LVS-DR. We don't have a solution yet (I don't
> think anyone has a fix on the problem). This didn't happen in older
> kernels
> (2.4.x) and we don't know when it appeared in the 2.6.x kernels.
> 
> > This happens only to 10 (guestimate) percent of all
> > connections.
> 
> other people have reported 1 event in 6hrs (I seem to remember)
> with a heavily loaded server.
> 
> Joe

-- 
Horms

<Prev in Thread] Current Thread [Next in Thread>