LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: AW: AW: SSL accelarators and LVS by Peter Baitz

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>, MKrauss@xxxxxxxxxxxxxx, Julian Anastasov <ja@xxxxxx>
Subject: Re: AW: AW: SSL accelarators and LVS by Peter Baitz
From: Joseph Mack <mack.joseph@xxxxxxx>
Date: Mon, 10 Mar 2003 14:58:21 -0500
Matthias Krauss wrote:
> 
> Joe wrote:
> 
> >what was your setup? accelarator box in front of the LVS (as below)?
> 
> I had 2 different test scenarios, 1st was apache directly on the director
> (running DR), were only the director answered the ssl request and nothing
> gots passed to the realservers,

(just getting this straight)
You had a LVS-DR director, but with apache listening on VIP:443 on the director.
I assume then that the director was not forwarding 443 to the realservers.
According to PB's write up, you'd then also need something listening on 80
on the director to handle the decrypted packets. Did you have this?

> I hoped to decrypt the packets on the director and then pass the decrypted
> packets to the realserver via the LVS

Julian,
        Can packets from an SSL accelerator listening on VIP:443 (but which
the LVS is not forwarding) and presumably outputting to VIP:80, be routed to 
ip_vs code? Presumably this would have to be LVS-NAT to get the packets on 
the way back.

Thanks JOe

-- 
Joseph Mack PhD, Senior Systems Engineer, SAIC contractor 
to the National Environmental Supercomputer Center, 
ph# 919-541-0007, RTP, NC, USA. mailto:mack.joseph@xxxxxxx
<Prev in Thread] Current Thread [Next in Thread>