Re: keepalived 1.1.20 nat not working

Thomas Elsäßer <[email protected]> Mon, 04 Oct 2010 12:48:58 +0200
Newsgroups gmane.linux.keepalived.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

OK. I have now only working with hardware lb. And here i say - i would
like nat the Loadbalancer change the client address with address of the
LB device or what i like.

OK i must use iptables to masquerade the traffic to real servers.
Understand i right?
Client   Paket: a.a.a.a  virt. ip XX.XX.XX.XX
||
||
||
||  eth0   IP: bb.bb.bb.bb
Linux LB
|| eth1    IP: cc.cc.cc.cc
||                          src           dst
||     Paket: i would like: cc.cc.cc.cc   dd.dd.dd.dd
||
Realserver  IP: dd.dd.dd.dd

Kind regards
Thomas

Am 04.10.2010 11:13, schrieb Martin Barry:
> $quoted_author =3D "Thomas Els=E4=DFer" ;
>>
>> i have the problem thaqt the nat not working. I use centos 5.5.
>> ipvsadm say all ok.
>>
>> IP Virtual Server version 1.2.1 (size=3D4096)
>> Prot LocalAddress:Port Scheduler Flags
>>   -> RemoteAddress:Port           Forward Weight ActiveConn InActConn
>> TCP  XX.XX.XX.XX:http wlc persistent 20
>>   -> 192.168.0.17:http            Masq    1      0          0
>>
>> But on the webserver (192.168.0.17) i see the original client address.
> =

> NAT only changes the server address.
> =

> Can you describe your configuration a bit more?
> =

> cheers
> Marty
> =

> -------------------------------------------------------------------------=
-----
> Virtualization is moving to the mainstream and overtaking non-virtualized
> environment for deploying applications. Does it make network security =

> easier or more difficult to achieve? Read this whitepaper to separate the =

> two and get a better understanding.
> http://p.sf.net/sfu/hp-phase2-d2d
> _______________________________________________
> Keepalived-announce mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/keepalived-announce

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJMqbEaAAoJEG7j5hDWI8HyisEH/27670xSrSNPIDWsq25c9Y1C
zh0knePfL2qVqoogo7gFURfp/9G+Eay1eXdJjN8gu8V/uznD8Xw7/YgD0qvUS3vr
wIR37i+g58xUBB/rihYB/Nzyf1LpClwvEdfM0S7khutYLeaV/dYGSp0cxaiRnMGU
WlAV+Zq4UJwVT/nupqWxKb4z7yLq86ajc1aesS410QyoT05AhulgjDaFwBhFueAc
GmwbfA5Ws9l70M4Fc6753/EMkfoQ5aJZf7/yKOlOV28XBglHH8Pri3ZvWuIXnVcz
N/f+4d0MBxq8BqtjRcIvFMbJXfZ0oNLl0VJ3KEsAPB8UYSXYGii0+BI9rt2E178=3D
=3DNw2m
-----END PGP SIGNATURE-----

---------------------------------------------------------------------------=
---
Virtualization is moving to the mainstream and overtaking non-virtualized
environment for deploying applications. Does it make network security =

easier or more difficult to achieve? Read this whitepaper to separate the =

two and get a better understanding.
http://p.sf.net/sfu/hp-phase2-d2d