Re: Keepalived and NAT loopback,.

Paul Robert Marino <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <CAPJdpdDx=rvvOJyAd9h2-9AyUoKkskYb7Yt=YV5+pMqSaWZCfA@mail.gmail.com>
sorry ive been swamped

so I still need more details

I'm assuming you have 3 public ips with a 1 to 1 two way (Source and
destination) static nat on two of them to two internal hosts with
private IPs
The third public IP is a VIP controlled as a VRRP instance in
keepalived and used by the load ballancer instance ballancing against
the other two public IPs
is this correct?

if not please tell me exactly how you have it configured.







On Tue, Aug 13, 2013 at 1:23 PM, Pat Suwalski <[email protected]> wrote:
> I guess there are no ideas about this?
>
> Thanks,
> --Pat
>
>
> On 13-08-05 12:04 AM, Pat Suwalski wrote:
>>
>> Thanks for that background.
>>
>> I have two sets of services that need load balancing and failover. We'll
>> say the first is on addresses 172.16.0.100 and 172.16.0.101, and is
>> visible on the internet as 200.1.2.3. The second is made up of
>> 172.16.0.200 and 172.16.0.201, on the internet as 200.1.2.10.
>>
>> The services running on the second service, 200.1.2.10, need to make
>> HTTP API calls to the 200.1.2.3. It needs to be to the virtual IP, for
>> load balancing and failover purposes.
>>
>> Looking at tcpdump, it is clear that the 172.16.0.100 and .101 servers
>> get the request to 200.1.2.3 as originating from 172.16.0.200, and
>> respond directly from their internal NAT address, making the response
>> ignored.
>>
>> The only solution I could possibly think of is to create another
>> (duplicate) stanza in the keepalived.conf file for 172.16.0.100/101, but
>> with an internal 172.16.0.x virtual IP. But I'd really rather not have
>> the duplication and second set of HTTP_GET checks.
>>
>> I'm sure there is a better solution to this problem. Maybe something as
>> simple as assigning a second (alias) virtual IP somehow, inside the
>> firewall.
>>
>> Thanks for reading,
>> --Pat
>>
>> On 13-08-04 06:58 PM, Paul Robert Marino wrote:
>>>
>>> Nat on a loopback is was deprecated (since kernel version 2.4) then
>>> disabled netfilters (in kernel version 2.6) along time ago and selinux
>>> blocks it too. The reason is its a potential massive security hole.
>>> You can do it via the dummy Ethernet driver which provides this kind of
>>> functionality however there are better way to do this.
>>>
>>> Please describe exactly what you are trying to do and well try to help
>>> you.
>>>
>>>
>>>
>>>
>>> -- Sent from my HP Pre3
>>>
>>> ------------------------------------------------------------------------
>>> On Aug 1, 2013 15:24, Pat Suwalski <[email protected]> wrote:
>>>
>>> Hello.
>>>
>>> (Apologies if this isn't the right place, I notice there is no -users
>>> list).
>>>
>>> I have a configuration using keepalived for Apache, set up pretty much
>>> exactly as described here:
>>>
>>> http://keepalived.org/LVS-NAT-Keepalived-HOWTO.html
>>>
>>> Now, I have a third internal server that is using the virtual internal
>>> IP as its gateway. I need this server to be able to access loadbalanced
>>> content. So, if the outside virtual address of keepalived is 1.2.3.4,
>>> that is what server three needs to get at.
>>>
>>> I can't seem to find a way to make this work. Using a "standard"
>>> loopback recipe with iptables, such as this one:
>>>
>>> http://for-invent.com/nat-loopback-using-iptables/
>>>
>>> is not doable, because the --to-destination is one of the two
>>> loadbalanced web servers.
>>>
>>> Has anyone managed to solve this?
>>>
>>> Many thanks,
>>> --Pat
>>>
>>>
>>> ------------------------------------------------------------------------------
>>>
>>>
>>> Get your SQL database under version control now!
>>> Version control is standard for application code, but databases havent
>>> caught up. So what steps can you take to put your SQL databases under
>>> version control? Why should you start doing it? Read more to find out.
>>>
>>> http://pubads.g.doubleclick.net/gampad/clk?id=49501711&iu=/4140/ostg.clktrk
>>>
>>> _______________________________________________
>>> Keepalived-devel mailing list
>>> [email protected]
>>> https://lists.sourceforge.net/lists/listinfo/keepalived-devel
>
>

------------------------------------------------------------------------------
Get 100% visibility into Java/.NET code with AppDynamics Lite!
It's a free troubleshooting tool designed for production.
Get down to code-level detail for bottlenecks, with <2% overhead. 
Download for free and get started troubleshooting in minutes. 
http://pubads.g.doubleclick.net/gampad/clk?id=48897031&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.