LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Does conntrack information survive LVS-NAT?

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: Does conntrack information survive LVS-NAT?
From: Joseph Mack NA3T <jmack@xxxxxxxx>
Date: Thu, 23 Jun 2005 11:48:07 -0700 (PDT)
On Thu, 23 Jun 2005, Nelson Castillo wrote:


My question is: Is the conntrack information set again on
the packages

packets :-)

that come back from the real servers to be routed by the director?

the fwmark only exists in the sk_buff. Once the packet leaves
the box, it is no longer fwmark'ed, ie the returning packets
are not marked.

I found this howto:

http://www.ssi.bg/~ja/nfct/HOWTO.txt

Do I need this ipvs-nfct patch?

probably. You need this with the standard kernel.

It seems it's not applied in the Debian sarge package I'm using.

You can never tell what's going to be in a non-standard kernel.

Joe
--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml Homepage http://www.austintek.com/ It's GNU/Linux!

<Prev in Thread] Current Thread [Next in Thread>