Re: Firewalling the load balancer

Horms <[email protected]>
Newsgroups gmane.linux.highavailability.ultramonkey
Message-ID <[email protected]>
Stefano Cislaghi <[email protected]> wrote:
> Hi all,
> 
> I'm deploying a structure with high availability and load balacing.
> Load balancer has a public ip on first interface. It's possibile to
> use iptables for firewalling external interface?

Yes, though keep in mind that packets handled by LVS will
won't appear in the FORWARDING chain. They also won't be handled
by conntrack unless you use a patch. As a guide:

http://www.vergenet.net/~horms/tmp/nf-lvs.png

> Maybe shorewall firewall. Is anyone using it?

Probably not, as it probably won't cope with the above restrictions.
Though that is just a wild guess.

-- 
Horms


-- 
Ultra Monkey - http://www.ultramonkey.org/
To UNSUBSCRIBE, email to [email protected], with a body:
unsubscribe ultramonkey-users [email protected]
where "[email protected]" is YOUR email address.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.