LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Reports of bad headers using TUN?

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: Reports of bad headers using TUN?
From: Joseph Mack NA3T <jmack@xxxxxxxx>
Date: Wed, 3 Jan 2007 15:25:42 -0800 (PST)
On Wed, 3 Jan 2007, Nigel Hamilton wrote:

So that means we know what the problem is now? We know that its packet fragmenting? I guess this one chick is behind some super-duper firewall that's not liking it?

No. Linux (and hence ip_vs) don't handle fragmentation for tunnelling properly. After you change the max packet size for packets from the director to the Tun realserver, then the client will be sent a "needs fragmenting" icmp packet. If this packet makes it back to the client, then your LVS should start working again.

Joe

--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!

<Prev in Thread] Current Thread [Next in Thread>