is this possible (multiple sources, replies go to proper source)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



In trying to figure out a LVS configuration to load balance firewallsI have gotten stuck with one problem.

the scenerio below is drasticly simplified, I can go into more detail if people think it would help.

inbound traffic to a box can arrive through either box B or box C (depending on factors outside this problem)

B   C
 \ /
  A
  |
  D

box A routes the traffic on to box D

box D replies to the connection (sending the packets to box A)

box A needs to figure out which box (B or C) the connection came through in the first place and use that as the gateway for the reply packets.

the nearest thing I can think of to a solution would be for box A to remember the MAC address that started the connection and then use it as the gateway for reply packets that are part of that connections. I don't know how to do this (or even if it's possible)

please copy me on replies as I am not subscribed to the list.

David Lang


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux