DNAT/PAT to multiple, public IPs instead of round-robin DNS ...

"Bryan J. Smith" <[email protected]>
Newsgroups gmane.linux.admin.managers
Message-ID <[email protected]>
[ My apologizes if this has been answered before.  I will not only summarize in detail, but will 
provide a "case study" to every relevant FAQ when I am done. ]

To this date, I have only done DNAT/PAT from a public IP to a private IP.

I have been considering using DNAT/PAT to multiple servers as a replacement for round-robin 
DNS that does not seem to be distributing our load well over servers.  But I have a small issue, all 
IPs are public.

We have a "front" public subnet (/29) with our firewall.  Then we have the public "back" subnet (/
26) with our servers.  We've only be using "forward" rules to date for services on the firewall to the 
"back" subnet.  The "default gateway" from the "back" subnet is the same as the firewall of the 
"front" subnet.

My concern is that if I add DNAT/PAT rules to this firewall, PAT might break since there is also a 
public IP route.  Now that route goes through the same box, the firewall, where the DNAT/PAT rule 
would be.  I just raised a flag after reading this section which did not clarify my circumstance (i.e. 
I'm trying to figure out what exactly is meant by "default route" -- system or IP?):  
  "PAT will break in strange and wonderful ways if there is an
    alternate route between the two hosts connected by the
    port address translation.
    [ http://linux-ip.net/html/nat-pat-userspace.html ]

I've looked at a few other sites, like LVS ( http://www.linuxvirtualserver.org ).  Most of the 
implementations there are completely failover (which is not something I can do, even minimally 
right now).  Would those lists be a better place to post such a question?


-- 
Bryan J. Smith, E.I.  mailto:[email protected]  http://thebs.org
_______________________________________________
LinuxManagers mailing list - http://www.linuxmanagers.org
submissions: LinuxManagers-35TzE1X9F6582KRnZfj+bdi2O/[email protected]
subscribe/unsubscribe: http://www.linuxmanagers.org/mailman/listinfo/linuxmanagers
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.