use_vmac questions.

Jan Hugo Prins <[email protected]>
Newsgroups gmane.linux.keepalived.devel
Message-ID <[email protected]>
Hi,

I'm doing some more digging around on use_vmac and I find some articles
that make me think that I should not use it:

1: http://www.serverphorums.com/read.php?10,304073,304073

This tells me that all traffic is coming from and going to the one vmac
interface. Is this correct? This would indeed break a lot of firewall
rules that depend on where the traffic enters a firewall. The way to
solve this would be to create a seperate VRRP instance for every
interface where you want to use a vmac interface, but in big firewalls
with a lot of interfaces this would become a real nightmare
configuration. This is true if I understand it correctly that all VRRP
IP addresses from all interfaces in the same VRRP_Instance should end up
on the same VMAC interface.

2: http://sourceforge.net/mailarchive/message.php?msg_id=31063933

The second post in this mail suggest that vmac interfaces are not stable
in any version of RedHat Enterprise or Centos, and should therefor not
be used until you have a distribution that uses kernel 3.2 or later. Is
this still correct, or did someone backport a lot of patches from 3.2 to
the kernels in RHEL?

Thanks,

Jan Hugo Prins






------------------------------------------------------------------------------
WatchGuard Dimension instantly turns raw network data into actionable 
security intelligence. It gives you real-time visual feedback on key
security issues and trends.  Skip the complicated setup - simply import
a virtual appliance and go from zero to informed in seconds.
http://pubads.g.doubleclick.net/gampad/clk?id=123612991&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.