[lvs-users] LVS SNAT latest kernel/iptables

To: <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: [lvs-users] LVS SNAT latest kernel/iptables
From: "Scrymgeour, James" <James.Scrymgeour@xxxxxxxxxxxxx>
Date: Wed, 1 Aug 2012 11:07:41 +0100


I have been trawling around the internet and your archives to try and
find a solution to a problem getting SNAT to work with lvs, I have
managed to get LVS working with the below configuration, however it
doesn't touch the iptables POSTROUTING table for the SNAT to take
affect. To prove this I have used tcpdump and seen the syn messages
going to my real servers without being snatted. I have also enabled
iptables logging on post routing but not a single log message appears,
the PREROUTING table can see all packets though.


I have seen similar questions in the mailing list but not a conclusive
answer to get this working, I have also seen the guide on:


which is basically what I have followed with my own IP's/Ports, without
the kernel/iptables compiling.


my basic configuration is:


Fedora 16 

Kernel - 3.1.0-7.fc16.i686 - confirmed the xt_ipvs module is there

Iptables - 1.4.12-2.fc16.i686

Ipvsadm - 1.26-3.fc16.i686


I have configured 2 ip's as:


And run the following commands to configure the lvs/snat

iptables -F -v 

ipvsadm -A -t -s rr
ipvsadm -a -t -r -m

iptables -t nat -A POSTROUTING -m ipvs --vaddr --vport
2001 -j SNAT --to-source


iptables -t nat -L shows
target     prot opt source               destination

Chain INPUT (policy ACCEPT)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

target     prot opt source               destination
SNAT       all  -  anywhere             anywhere            vaddr vport 80 to:


ipvsadm -ln displays
IP Virtual Server version 1.2.1 (size=4096)
Prot LocalAddress:Port Scheduler Flags
-> RemoteAddress:Port           Forward Weight ActiveConn InActConn
TCP rr
->              Masq    1      0          0


I have attempted doing this using unused IP addresses however it doesn't
accept any connections on the virtual servers.


TCPDUMP shows receiving the syn

The syn being sent to but the source still being


Thanks for your help


This e-mail from Ultra Electronics Limited and any attachments to it are 
confidential to
the intended recipient and may also be privileged. If you have received it in 
error please
notify the sender and delete it from your system. If you are not the intended 
you must not copy it or use it for any purpose nor disclose or distribute its 
contents to 
any other person. All communications may be subject to interception or 
monitoring for 
operational and/or security purposes. Please rely on your own virus checking as 
the sender 
cannot accept any liability for any damage arising from any bug or virus 
Ultra Electronics Limited is a company registered in England and Wales, 
registration number 
2830644. The address of its registered office is 417 Bridport Road, Greenford, 
Middlesex, UB6 8UA.
Please read the documentation before posting - it's available at: mailing list - lvs-users@xxxxxxxxxxxxxxxxxxxxxx
Send requests to lvs-users-request@xxxxxxxxxxxxxxxxxxxxxx
or go to

<Prev in Thread] Current Thread [Next in Thread>
  • [lvs-users] LVS SNAT latest kernel/iptables, Scrymgeour, James <=