Re: Ipv6 and preferred_lft

Martinsson Patrik <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <FE20F28599789F41A422C6098507C984BCEEAF25@winserv302>
Hi again, 

Well the problem with using the bindo-parameter is exactly that the setting is not applied system-wide. 
Now you will have two different behaviours, one with traffic going through keepalived, and another one with "regular system traffic" (eg. ping). 

So what you will get doing it that way is a correct behaviour regarding keepalived's traffic, however the system traffic (eg. a ping) would still end up sending a packet with the src-address of the last added vip. 
In my opinion that is even more wrong. 

I still don't understand why you would want to have the vip's address as the source-address of the traffic leaving the server, rather then the *actual* ip-address. 
What's the main difference between ipv4 and ipv6 in this particular case ? I mean, if the source-address would be the vip-address when using ipv4 we would have the same problem, however it's not, its the *actual* ip-adress of the server. 

Maybe I'm missing a huge point here since I'm not a network-engineer, but from my point of view the whole thing seems pretty straight forward - that is, don't use the vip's addresses as source for outgoing traffic (and yes, I have looked at the packets, and they do indeed have the latest added vip as source-addr).  

Patrik Martinsson
ITi

SMHI
Telefon 011 - 495 84 17 Fax 011 - 495 83 50
Mobil 011 - 495 84 17 Epost [email protected]
601 76 Norrköping Besöksadress Folkborgsvägen 1
www.smhi.se

________________________________________
From: Ryan O'Hara [[email protected]]
Sent: Thursday, August 29, 2013 15:52
To: Mark Schouten
Cc: [email protected]
Subject: Re: [Keepalived-devel] Ipv6 and preferred_lft

On Tue, Aug 27, 2013 at 10:19:28PM +0200, Mark Schouten wrote:
> Hi,
>
> in response to the message by Martinsson Patrik
> (http://article.gmane.org/gmane.linux.keepalived.devel/4252). I too have
> suffered from the fact that VRRP-addresses are not added with a
> preferred_lft of 0. This resulted in checks being done with a one of the
> vip-addresses as source address.
>
> I thought that I could put 'iproute2'-commands in the config, but that
> wasn't the case.
>
> "2a03:7900:1:3:31:3:104:121 dev eth0 preferred_lft 0" in the
> virtual_ipaddress-stanza results in the IP not being added and a error
> in syslog:
>  VRRP is trying to assign invalid VIP preferred_lft. skipping VIP...
>
> So that doesn't work.
>
> IMHO, a VIP-address should be added with preferred_lft 0 by default,
> unless a netmask other than /128 is specified.

I think the problem with using preferred_lft 0 when creating the VIP
is that it had system-wide implications.

The solution here is to use the bindto parameter in your healthcheck
configuration. This should prevent healthchecks from having VIP as
source address.

Ryan


------------------------------------------------------------------------------
Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more!
Discover the easy way to master current and previous Microsoft technologies
and advance your career. Get an incredible 1,500+ hours of step-by-step
tutorial videos with LearnDevNow. Subscribe today and save!
http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk
_______________________________________________
Keepalived-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/keepalived-devel

------------------------------------------------------------------------------
Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more!
Discover the easy way to master current and previous Microsoft technologies
and advance your career. Get an incredible 1,500+ hours of step-by-step
tutorial videos with LearnDevNow. Subscribe today and save!
http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.