hmmm so you're saying that the LVS acts as a web gw?
that all the traffic goes back to the LVS and then to the client?
so i don't need to have a firewall and site-to-site?
Just make the LVS with 2 nics, iptables, and do LVS-TUN?

and well that's the other thing: where's a good howto on setting up a
TUN with LVS...what software, ipsec?, etc
I'm using centOS 5.1, but I could go to another distro, if its
specifically made for LVS...

