On Sun, 7 Oct 2007, Joseph Mack NA3T wrote:
> On Sun, 7 Oct 2007, ipvs user wrote:
>
>> but I coulda swore I read something to that effect,
>> because I remember thinking "Note to self: don't use
>> iptables on high connection rate systems".
there are other problems due to collisions within the logic
of ip_vs() and netfilter, which are left over from the
design of ip_vs(), which result in packets not getting
through at all if you use the wrong iptables rules. For this
reason we advise people not to use iptables rules (except
for transparent proxy) until their LVS is running. These
problems are in principle fixable, but no-one has taken the
time to do this.
Joe
--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!
|