use_vmac questions.
Jan Hugo Prins <[email protected]>
| Newsgroups | gmane.linux.keepalived.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, I'm doing some more digging around on use_vmac and I find some articles that make me think that I should not use it: 1: http://www.serverphorums.com/read.php?10,304073,304073 This tells me that all traffic is coming from and going to the one vmac interface. Is this correct? This would indeed break a lot of firewall rules that depend on where the traffic enters a firewall. The way to solve this would be to create a seperate VRRP instance for every interface where you want to use a vmac interface, but in big firewalls with a lot of interfaces this would become a real nightmare configuration. This is true if I understand it correctly that all VRRP IP addresses from all interfaces in the same VRRP_Instance should end up on the same VMAC interface. 2: http://sourceforge.net/mailarchive/message.php?msg_id=31063933 The second post in this mail suggest that vmac interfaces are not stable in any version of RedHat Enterprise or Centos, and should therefor not be used until you have a distribution that uses kernel 3.2 or later. Is this still correct, or did someone backport a lot of patches from 3.2 to the kernels in RHEL? Thanks, Jan Hugo Prins ------------------------------------------------------------------------------ WatchGuard Dimension instantly turns raw network data into actionable security intelligence. It gives you real-time visual feedback on key security issues and trends. Skip the complicated setup - simply import a virtual appliance and go from zero to informed in seconds. http://pubads.g.doubleclick.net/gampad/clk?id=123612991&iu=/4140/ostg.clktrk