LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

[lvs-users] netfilter match for ipvs connections

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: [lvs-users] netfilter match for ipvs connections
From: Siim Põder <windo@xxxxxxxxxxxxxxx>
Date: Wed, 16 Apr 2008 09:08:56 +0300
Yo!

I'll ask again, as I think someone might yet have an opinion on this:

Would it make sense in having a netfilter match that would look up
connections on ipvs connection table? That would allow for filtering
outbound packets in FORWARD without having to export the connections to
conntrack and for a more consistent action as the outbound check would
be the same as the inbound check (based on ipvs knowledge of the
connection).

And also, are there maybe peculiarities of ipvs connection tables that
would make this infeasible? I'd be willing to look into it, if there was
some opinion of it making sense.

Siim



<Prev in Thread] Current Thread [Next in Thread>