Re: Firewalling the load balancer
Horms <[email protected]>
| Newsgroups | gmane.linux.highavailability.ultramonkey |
|---|---|
| Message-ID | <[email protected]> |
Stefano Cislaghi <[email protected]> wrote: > Hi all, > > I'm deploying a structure with high availability and load balacing. > Load balancer has a public ip on first interface. It's possibile to > use iptables for firewalling external interface? Yes, though keep in mind that packets handled by LVS will won't appear in the FORWARDING chain. They also won't be handled by conntrack unless you use a patch. As a guide: http://www.vergenet.net/~horms/tmp/nf-lvs.png > Maybe shorewall firewall. Is anyone using it? Probably not, as it probably won't cope with the above restrictions. Though that is just a wild guess. -- Horms -- Ultra Monkey - http://www.ultramonkey.org/ To UNSUBSCRIBE, email to [email protected], with a body: unsubscribe ultramonkey-users [email protected] where "[email protected]" is YOUR email address.