On Thu, 19 Jul 2007, Jessie wrote:
> Update-
>
> I discovered the problem lies in routing. Our director is newly multi-
> homed and it seems that whichever interface our default gw lies, will
> allow the LVS-DR to actually work. So for all other interfaces on the
> director, the VIP instances will no longer work outside of the subnet.
you've done something funny with the routing.
I assume there's clients on your LAN and clients coming from
the internet. They all should have a route to the VIP (which
I assume is on the outside/internet side of the director)
even if the clients on the LAN have to make a short hop to
the internet first.
The director doesn't need (and for security shouldn't have)
a default gw for tcp/udp packets from the VIP - all return
packets come from the VIP on the realservers.
> What are people doing for multi homed LVS boxes?
we haven't had the problem before.
Joe
--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!
|