LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

new question - iptables on LB and connection limit?

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: new question - iptables on LB and connection limit?
From: Larry Ludwig <ludes@xxxxxxxxx>
Date: Tue, 14 Nov 2006 06:44:06 -0800 (PST)
New questions

1.  We are using LVS-DR and want to have iptables enabled on the LB.  When we 
did this our apachebench tests eventually failed to connect to the load 
balancer.  Once we disabled the firewall or wait a few min to test again 
everything worked.  I can say for sure it's 100% related to the firewall being 
enabled and nothing else.

My question, what's the best setup of an iptables firewall to use with with 
LVS-DR?  Does iptables have some connection limit per IP that automaticly 
blocks a connection after a large amount of requests (in our case apachebench 
is coming from one IP)

2.  Also we seem to max out at 30k connections on our testing, and appears to 
be some hard limit withing ipvsadm?  How can we increase this?  The server has 
2GB of RAM (I know way too much but bought all hardware in bulk) so it has 
plenty of ram.  No matter how many connectons we throw at it using apachebench 
we can't get it past that #.

thanks again.



 
____________________________________________________________________________________
Want to start your own business?
Learn how on Yahoo! Small Business.
http://smallbusiness.yahoo.com/r-index

<Prev in Thread] Current Thread [Next in Thread>