On Mon, 21 Jul 2008, Dimitri GOURDON wrote:
> I don't understand where you want to go... If I have no iptables rule,
> all is OK as I say in my first message.
I can't find where you say that in your first message.
> The problem is I use iptables to do state filtering and
> all FIN / RST packet are seen as INVALID (instead of
> ESTABLISHED...).
are you using LVS-DR? If so you can't use stateful filtering
on the director, because the director doesn't see the reply
packets from the realserver.
> The solution mustn't be to remove iptables rules ;)
yes it is.
Joe
--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!
|