LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Active ftp w/ lvs NAT broken?

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: Active ftp w/ lvs NAT broken?
From: Joseph Mack NA3T <jmack@xxxxxxxx>
Date: Wed, 23 Nov 2005 16:32:59 -0800 (PST)
On Wed, 23 Nov 2005, Graeme Fowler wrote:

Yes, netfilter/iptables does interact with LVS.

Under LVS-NAT you need to make sure that the traffic exiting the director on the client side is what the client expects. That means SNAT (or masquerade).

the original implementation doesn't need any iptables rules; the ftp helper and the lvs code handle it all. Unless there's a change in spec (intentional that no-one has made clear, or unintentional through bitrot), you still shouldn't need iptables rules.

Joe

--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml Homepage http://www.austintek.com/ It's GNU/Linux!

<Prev in Thread] Current Thread [Next in Thread>