Re: Piranha (LVS) + Firewall (Shorewall) on the same box
Mike McLean <[email protected]>
| Newsgroups | gmane.linux.redhat.piranha |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
ipvs and ipchains/iptables can coexist, in fact many useful Piranha configurations require a little help (such as packet marking) from one or the other. You do have to be a little more careful with your firewall rules. Usually this won't be any issue, but it is possible to make these two routing mechanisms conflict. In particular, setting up both LVS-NAT and a masquerading firewall can cause problems if you don't do it just right. Ed Crotty wrote: > Has anyone had any experience putting a firewall and Piranha/LVS (NAT) on the same box? Are there any gotchas to look out for / special considerations? > > In the case of shorewall, you can setup your NAT enviornment within the firewall.. Would I be correct in assuming I just need to make sure the Real Servers can talk to the firewall and allow port 80 traffic to hit the public firewall (virutal interfaces for real servers) interface and all is well? > > Thanks! > -ed > > ************************************************************************** > This e-mail and any files transmitted with it are intended for the use of the addressee(s) only and may be confidential and covered by the attorney/client and other privileges. If you received this e-mail in error, please notify the sender; do not disclose, copy, distribute, or take any action in reliance on the contents of this information; and delete it from your system. Any other use of this e-mail is prohibited. > > > > _______________________________________________ > Piranha-list mailing list > [email protected] > https://listman.redhat.com/mailman/listinfo/piranha-list