RE: Accessing the file system of clustered machines

Karl Wyant <[email protected]>
Newsgroups gmane.linux.redhat.piranha
Message-ID <a05100308b937e10d9cc6@[192.168.5.2]>
I'm not entirely certain I understand your request, but it seems to 
me that you are asking for a M$ style file system (aka network 
neighborhood) to go through the lvs router.  I've never experimented 
with that and know nothing about its possibilities.  I think that 
might be netbeui instead of tcp/ip though.  What I do for updates 
that works very nicely is scp directly to the lvs router.  Then a 
cron script scp's the updates directly to the internal servers 
addressing the internal machines via their internal ip#'s.  If such a 
solution is not acceptable, you might be able to use samba somehow to 
your advantage.  In my opinion, though; if the internal machines file 
structures can be seen outside the internal cluster, then that 
provides a security risk.

Other ideas.  If it is only the one development server, you could add 
a second nic to it and plug the second nic into the internal switch. 
That would let you see the internal machines, but then the 
development server becomes a nice bridge to attack directly into your 
internal cluster without the protection of your lvs 
controller/firewall.

Anyway, hope all this rambling was of at least some use.

Karl



>That is what I'm trying to do.  We have a development server that is 
>outside the cluster.  When I take off the public NIC I can't access 
>the file system of the clustered servers but I can ping them.  Also 
>when the public NIC on the clustered servers is disabled I can 
>browse the file systems of any other machine on our public network, 
>I just don't understand why I can't browse back to the clustered 
>servers.  I know, I know, I'm trying to get away from M$ server but 
>you know what it's like to get the managing director to make a 
>change for the better!! :0)
>
>-----Original Message-----
>From: Karl Wyant [mailto:[email protected]]
>Sent: Wednesday, June 19, 2002 6:07 PM
>To: [email protected]
>Subject: Re: Accessing the file system of clustered machines
>
>
>The prior answer is correct that your webservers, especially M$ ones
>should not have a public nic.  Let piranha and a nice firewall
>minimize your headaches.  Replication can either be handled from
>inside the cluster or if it must come from outside the cluster, have
>the lvs controller machine actually handle the distribution via the
>internal ip#'s of your cluster.  This approach is much safer than
>hanging a M$ machine outside.
>
>
>>OK here is the situation,  I have two lvs 1 primary and 1 secondary
>>machine with four clustered Microsoft web servers each web server
>>has two NIC cards, one has a public IP address and the other has a
>>private ( 192.168.0.0).  The problem is that when setup like that I
>>can't type in the clustered domain name i.e. www.domainname.com and
>>pull up the website, but if I disable the public card on the web
>>servers it's not a problem.  Then I can't access the file system on
>>the web servers for replication of new files.  Sorry for the book
>>and I really appreciate any help.
>>
>>Thank you,
>  >Nick

-- 
Karl Wyant
[email protected]
http://www.saturnsys.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.