LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: [Keepalived-devel] Does conntrack information survive LVS-NAT?

To: keepalived-devel@xxxxxxxxxxxxxxxxxxxxx, lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Subject: Re: [Keepalived-devel] Does conntrack information survive LVS-NAT?
From: Mack.Joseph@xxxxxxxxxxxxxxx
Date: Thu, 23 Jun 2005 09:18:47 -0400
Joseph Mack PhD, High Performance Computing & Scientific Visualisation
LMIT, Supporting the EPA Research Triangle Park, NC 919-541-0007 Federal
Infrastructure Contact-Ravi Nair 919-541-5467 - nair.ravi@xxxxxxx,
Federal Visualization  Contact - Joe Retzer, Ph.D. 919-541-4190 -
retzer.joseph@xxxxxxx

keepalived-devel-admin@xxxxxxxxxxxxxxxxxxxxx wrote on 06/22/2005
06:02:31 PM:


> My question is: Is the conntrack information set again on
> the packages

packets :-)

> that come back from the real servers to be routed by the director?

the fwmark only exists in the sk_buff. Once the packet leaves
the box, it is no longer fwmark'ed, ie the returning packets
are not marked.


> I found this howto:
>
> http://www.ssi.bg/~ja/nfct/HOWTO.txt
>
> Do I need this ipvs-nfct patch?

probably. You do with the standard kernel.

> It seems it's not applied in the Debian sarge package I'm using.

You can never tell what's going to be in a non-standard kernel.

Joe


<Prev in Thread] Current Thread [Next in Thread>
  • Re: [Keepalived-devel] Does conntrack information survive LVS-NAT?, Mack . Joseph <=