Re: [lvs-users] IPVS and IPTABLES firewall

To: " users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: [lvs-users] IPVS and IPTABLES firewall
Cc: graeme@xxxxxxxxxxx
From: Joseph Mack NA3T <jmack@xxxxxxxx>
Date: Tue, 14 Apr 2009 05:39:15 -0700 (PDT)
On Tue, 14 Apr 2009, w y wrote:

I have installed a basic http loadbalancing  that work perfectly :

Internet <-> LVS/VIP <-> RIP (1 machine)

I don't know how you can tell it's working unless you have two realservers

But unfortunalty, when I run my "usual" firewall script to protect my director server (ie some IPTABLES commands to only allow port 80), loadbalancing is broken

only add rules that work.

You can't use stateful filtering as the director doesn't see the reply packets

   Do you mean that we don't ne to patch the kernel ?

you can figure it out from the HOWTO. Sorry it's been so long since I wrote that stuff, and I don't use it myself, that I don't know the answer anymore


Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at
Homepage It's GNU/Linux!
Please read the documentation before posting - it's available at: mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
or go to
<Prev in Thread] Current Thread [Next in Thread>