LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

[lvs-users] Multiple HTTPS (per real-server) on LVS-DR does not work

To: lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Subject: [lvs-users] Multiple HTTPS (per real-server) on LVS-DR does not work
From: Michael Moody <michael@xxxxxx>
Date: Tue, 16 Oct 2007 17:48:39 -0700
I have LVS-DR on gentoo 2006.1, kernel 2.6.20.

Apache 2.0

I am running multiple ssl vhosts (ip-based) on each realserver.

The load balancer has two vips, 10.0.0.20(https site 1), and 
10.0.0.24(https site 2)

I have two rip's on each realserver,
[192.168.1.20(https1) and 192.168.1.23(https2) (server1)]
[198.168.1.54(https1) and 192.168.1.24(https2) (server2)]

The vhost conf looks like this:

Server 1:
NameVirtualHost 192.168.1.20:443
<VirtualHost 192.168.1.20:443>

NameVirtualHost 192.168.1.23:443
<VirtualHost 192.168.1.23:443>

Server2:

NameVirtualHost 192.168.1.24:443
<VirtualHost 192.168.1.24:443>

NameVirtualHost 192.168.1.54:443
<VirtualHost 192.168.1.54:443>

However, if I go to the vip, via https://10.0.0.20, I get an ssl error. 
What it appears like to me is that since apache is listening on 
192.168.1.24, it can't respond to requests from the load balancer since 
it's not also listening on the vip. Is there a way to make it listen on 
the vip as well? What am I doing wrong?

Thanks,
Michael

-- 

Michael S. Moody
Systems Engineer
Global Systems Consulting
Direct: (650) 265-4154
Web: http://www.GlobalSystemsConsulting.com

Engineering Support: support@xxxxxx
Billing Support: billing@xxxxxx
Customer Support Portal:  http://my.gsc.cc


NOTICE - This message contains privileged and confidential information intended 
only for the use of the addressee named above. If you are not the intended 
recipient of this message, you are hereby notified that you must not 
disseminate, copy or take any action in reliance on it. If you have received 
this message in error, please immediately notify Global Systems Consulting, its 
subsidiaries or associates. Any views expressed in this message are those of 
the individual sender, except where the sender specifically states them to be 
the view of Global Systems Consulting, its subsidiaries and associates.



<Prev in Thread] Current Thread [Next in Thread>