Re: Having problems loadbalancing ICAP protocol (tcp 1344)

Ken Thurman <[email protected]> Fri, 7 May 2010 17:50:30 -0400
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============0803218855==
Content-Type: multipart/alternative; boundary=0016364270fe42bf1a0486080c61

--0016364270fe42bf1a0486080c61
Content-Type: text/plain; charset=ISO-8859-9
Content-Transfer-Encoding: quoted-printable

Well that first session table dump looked strange, the U flag means that it
was doing some layer 7 processing to pick the real server to bind the
connection to. That is why I asked to see the VIP configuration when it was
failing, do you have any layer7 processing enabled?

-ken

On Fri, May 7, 2010 at 3:01 PM, Cihan Subasi (Garanti Teknoloji) <
[email protected]> wrote:

> I can telnet to servers to tcp 1344, the frontend webservers send all
> uploaded contents to symantec content check engines on those 2 servers
> accepting connections wth ICAP (tcp1344). But servers cannot establish
> connection to tcp1344 on virtual IP when I change my "service" to IP from
> tcp1344, it works fine...giving tcp1344 to services does not work. This i=
s a
> 180E with 10.0.33 code on it...
>
> From the session table I can see server is coming to virt but real server
> is also virt...strange
>
> 10.145.2.133 is the virtual ip on alteon
>
> 10.129.0.237 2216, *10.145.2.133* 1344 -> 5841 *10.145.2.133*
>
>
>
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On Behalf Of
> Cl=E9ment Game
> Sent: Friday, May 07, 2010 3:12 PM
> To: Load Balancing Mailing List
> Subject: Re: [load balancing] Having problems loadbalancing ICAP protocol
> (tcp 1344)
>
> I also have some issues with ICAP load balancing but at least my director
> can establish connections. Usually ICAP behaves like HTTP with more or le=
ss
> the same syntax. ( QUERY_TYPE PARAM ICAP/1.0 ) ; so nothing apparently
> prevents ICAP to be used in a load balanced way. But like http 1.1, ICAP
> allows you to make persistant connections/pipelining and this clearly is =
a
> bad way to do things in a load balanced environement.
>
> Connect to your load balancer and check if you can telnet to your symante=
c
> servers on port 1344 from here. maybe that it's just an ACL issue on the
> symantec servers side...also make sure that your symantec servers listen
> correctly and are bound to the correct ip(s) with netstat.
>
> Also i presume that you're using a frontend proxy to forward content to
> your icap servers right ? Which one is it ? It would be valuable for you =
to
> know how the internal icap client of this proxy server behaves.
>
> Regards,
>
> Cl=E9ment.
>
>
>
>
>
>
> Cihan Subasi (Garanti Teknoloji) wrote:
> > I am trying to load balance ICAP on 2 symantec content check servers,
> > they both set to tcp 1344, all seem ok, but I cannot establish
> > connection? I am thing that ICAP is not loadbalanceable...What do you
> > think? thank you Alteon shows me virtual address and real address are
> > same...
> > >> Session Table Information# cip 10.129.0.237
> > 7,1745: 10.129.0.237 2216, *10.145.2.133* 1344 -> 5841 *10.145.2.133*
> > 1344 age 4 EU
> >
> > Cihan Suba=FE=FD
> > Network Y=F6netimi
> > Y=F6netici      Evren Mahallesi, Ko=E7man Caddesi No:34 G=FCne=FEli 342=
12
> =DDstanbul
> > Tel   :       +90 212 478 35 35
> > Direkt        :       +90 212 478 34 26
> > Faks  :       +90 212 657 04 73
> >
> >
> >
> >
> > This message and attachments are confidential and intended solely for
> > the individual(s) stated in this message. If you received this message
> > although you are not the addressee, you are responsible to keep the
> > message confidential. The sender has no responsibility for the
> > accuracy or correctness of the information in the message and its
> > attachments. Our company shall have no liability for any changes or
> > late receiving, loss of integrity and confidentiality, viruses and any
> > damages caused in anyway to your computer system.
> >
> > Bu mesaj ve ekleri, mesajda gonderildigi belirtilen kisi/kisilere
> > ozeldir ve gizlidir. Bu mesajin muhatabi olmamaniza ragmen tarafiniza
> > ulasmis olmasi halinde mesaj iceriginin gizliligi ve bu gizlilik
> > yukumlulugune uyulmasi zorunlulugu tarafiniz icin de soz konusudur.
> > Mesaj ve eklerinde yer alan bilgilerin dogrulugu ve guncelligi
> > konusunda gonderenin ya da sirketimizin herhangi bir sorumlulugu
> > bulunmamaktadir. Sirketimiz mesajin ve bilgilerinin size degisiklige
> > ugrayarak veya gec ulasmasindan, butunlugunun ve gizliliginin
> > korunamamasindan, virus icermesinden ve bilgisayar sisteminize
> > verebilecegi herhangi bir zarardan sorumlu tutulamaz.
> >
> > ----------------------------------------------------------------------
> > --
> >
> > _______________________________________________
> > lb-l mailing list
> > [email protected]
> > http://vegan.net/mailman/listinfo/lb-l
> > Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com
> > Load Balancing Digest http://lbwiki.com Load Balancing Wiki
> >
>
> _______________________________________________
> lb-l mailing list
> [email protected]
> http://vegan.net/mailman/listinfo/lb-l
> Searchable Archive: http://vegan.net/lb/archive
> http://lbdigest.com Load Balancing Digest
> http://lbwiki.com Load Balancing Wiki
> _______________________________________________
> lb-l mailing list
> [email protected]
> http://vegan.net/mailman/listinfo/lb-l
> Searchable Archive: http://vegan.net/lb/archive
> http://lbdigest.com Load Balancing Digest
> http://lbwiki.com Load Balancing Wiki
>

--0016364270fe42bf1a0486080c61
Content-Type: text/html; charset=ISO-8859-9
Content-Transfer-Encoding: quoted-printable

Well that first session table dump looked strange, the U flag means that it=
 was doing some layer 7 processing to pick the real server to bind the conn=
ection to. That is why I asked to see the VIP configuration when it was fai=
ling, do you have any layer7 processing enabled?<br>
<br>-ken<br><br><div class=3D"gmail_quote">On Fri, May 7, 2010 at 3:01 PM, =
Cihan Subasi (Garanti Teknoloji) <span dir=3D"ltr">&lt;<a href=3D"mailto:Ci=
[email protected]">[email protected]</a>&gt;</span> wrote:<br><blockq=
uote class=3D"gmail_quote" style=3D"margin: 0pt 0pt 0pt 0.8ex; border-left:=
 1px solid rgb(204, 204, 204); padding-left: 1ex;">
I can telnet to servers to tcp 1344, the frontend webservers send all uploa=
ded contents to symantec content check engines on those 2 servers accepting=
 connections wth ICAP (tcp1344). But servers cannot establish connection to=
 tcp1344 on virtual IP when I change my &quot;service&quot; to IP from tcp1=
344, it works fine...giving tcp1344 to services does not work. This is a 18=
0E with 10.0.33 code on it...<br>

<br>
From the session table I can see server is coming to virt but real server i=
s also virt...strange<br>
<br>
10.145.2.133 is the virtual ip on alteon<br>
<div class=3D"im"><br>
10.129.0.237 2216, *10.145.2.133* 1344 -&gt; 5841 *10.145.2.133*<br>
<br>
<br>
<br>
</div><div class=3D"im">-----Original Message-----<br>
From: <a href=3D"mailto:[email protected]">[email protected]</a> =
[mailto:<a href=3D"mailto:[email protected]">[email protected]</a=
>] On Behalf Of Cl=E9ment Game<br>
Sent: Friday, May 07, 2010 3:12 PM<br>
To: Load Balancing Mailing List<br>
Subject: Re: [load balancing] Having problems loadbalancing ICAP protocol (=
tcp 1344)<br>
<br>
</div><div><div></div><div class=3D"h5">I also have some issues with ICAP l=
oad balancing but at least my director can establish connections. Usually I=
CAP behaves like HTTP with more or less the same syntax. ( QUERY_TYPE PARAM=
 ICAP/1.0 ) ; so nothing apparently prevents ICAP to be used in a load bala=
nced way. But like http 1.1, ICAP allows you to make persistant connections=
/pipelining and this clearly is a bad way to do things in a load balanced e=
nvironement.<br>

<br>
Connect to your load balancer and check if you can telnet to your symantec =
servers on port 1344 from here. maybe that it&#39;s just an ACL issue on th=
e symantec servers side...also make sure that your symantec servers listen =
correctly and are bound to the correct ip(s) with netstat.<br>

<br>
Also i presume that you&#39;re using a frontend proxy to forward content to=
 your icap servers right ? Which one is it ? It would be valuable for you t=
o know how the internal icap client of this proxy server behaves.<br>
<br>
Regards,<br>
<br>
Cl=E9ment.<br>
<br>
<br>
<br>
<br>
<br>
<br>
Cihan Subasi (Garanti Teknoloji) wrote:<br>
&gt; I am trying to load balance ICAP on 2 symantec content check servers,<=
br>
&gt; they both set to tcp 1344, all seem ok, but I cannot establish<br>
&gt; connection? I am thing that ICAP is not loadbalanceable...What do you<=
br>
&gt; think? thank you Alteon shows me virtual address and real address are<=
br>
&gt; same...<br>
&gt; &gt;&gt; Session Table Information# cip 10.129.0.237<br>
&gt; 7,1745: 10.129.0.237 2216, *10.145.2.133* 1344 -&gt; 5841 *10.145.2.13=
3*<br>
&gt; 1344 age 4 EU<br>
&gt;<br>
&gt; Cihan Suba=FE=FD<br>
&gt; Network Y=F6netimi<br>
&gt; Y=F6netici =A0 =A0 =A0Evren Mahallesi, Ko=E7man Caddesi No:34 G=FCne=
=FEli 34212 =DDstanbul<br>
&gt; Tel =A0 : =A0 =A0 =A0 +90 212 478 35 35<br>
&gt; Direkt =A0 =A0 =A0 =A0: =A0 =A0 =A0 +90 212 478 34 26<br>
&gt; Faks =A0: =A0 =A0 =A0 +90 212 657 04 73<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; This message and attachments are confidential and intended solely for<=
br>
&gt; the individual(s) stated in this message. If you received this message=
<br>
&gt; although you are not the addressee, you are responsible to keep the<br=
>
&gt; message confidential. The sender has no responsibility for the<br>
&gt; accuracy or correctness of the information in the message and its<br>
&gt; attachments. Our company shall have no liability for any changes or<br=
>
&gt; late receiving, loss of integrity and confidentiality, viruses and any=
<br>
&gt; damages caused in anyway to your computer system.<br>
&gt;<br>
&gt; Bu mesaj ve ekleri, mesajda gonderildigi belirtilen kisi/kisilere<br>
&gt; ozeldir ve gizlidir. Bu mesajin muhatabi olmamaniza ragmen tarafiniza<=
br>
&gt; ulasmis olmasi halinde mesaj iceriginin gizliligi ve bu gizlilik<br>
&gt; yukumlulugune uyulmasi zorunlulugu tarafiniz icin de soz konusudur.<br=
>
&gt; Mesaj ve eklerinde yer alan bilgilerin dogrulugu ve guncelligi<br>
&gt; konusunda gonderenin ya da sirketimizin herhangi bir sorumlulugu<br>
&gt; bulunmamaktadir. Sirketimiz mesajin ve bilgilerinin size degisiklige<b=
r>
&gt; ugrayarak veya gec ulasmasindan, butunlugunun ve gizliliginin<br>
&gt; korunamamasindan, virus icermesinden ve bilgisayar sisteminize<br>
&gt; verebilecegi herhangi bir zarardan sorumlu tutulamaz.<br>
&gt;<br>
&gt; ----------------------------------------------------------------------=
<br>
&gt; --<br>
&gt;<br>
&gt; _______________________________________________<br>
&gt; lb-l mailing list<br>
&gt; <a href=3D"mailto:[email protected]">[email protected]</a><br>
&gt; <a href=3D"http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">h=
ttp://vegan.net/mailman/listinfo/lb-l</a><br>
&gt; Searchable Archive: <a href=3D"http://vegan.net/lb/archive" target=3D"=
_blank">http://vegan.net/lb/archive</a> <a href=3D"http://lbdigest.com" tar=
get=3D"_blank">http://lbdigest.com</a><br>
&gt; Load Balancing Digest <a href=3D"http://lbwiki.com" target=3D"_blank">=
http://lbwiki.com</a> Load Balancing Wiki<br>
&gt;<br>
<br>
_______________________________________________<br>
lb-l mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]</a><br>
<a href=3D"http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http:/=
/vegan.net/mailman/listinfo/lb-l</a><br>
Searchable Archive: <a href=3D"http://vegan.net/lb/archive" target=3D"_blan=
k">http://vegan.net/lb/archive</a><br>
<a href=3D"http://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> L=
oad Balancing Digest<br>
<a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> Load =
Balancing Wiki<br>
_______________________________________________<br>
lb-l mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]</a><br>
<a href=3D"http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http:/=
/vegan.net/mailman/listinfo/lb-l</a><br>
Searchable Archive: <a href=3D"http://vegan.net/lb/archive" target=3D"_blan=
k">http://vegan.net/lb/archive</a><br>
<a href=3D"http://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> L=
oad Balancing Digest<br>
<a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> Load =
Balancing Wiki<br>
</div></div></blockquote></div><br>

--0016364270fe42bf1a0486080c61--

--===============0803218855==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0803218855==--