Re: Second failover failure with conntrackd - INVALID packets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Pablo Neira Ayuso wrote:
Yoann Juet wrote:
Pablo Neira Ayuso wrote:
Pablo Neira Ayuso wrote:
Please, add the following line here to your scripts:

conntrackd -B -C /etc/conntrackd.conf

Let me now if that fixes your problem.

Updates? I'm intrigued with your problem. Some more info for
troubleshooting. You have the commands:

display internal cache (states that belong to this node)
# conntrackd -i

display external cache (states that belong to other nodes)
# conntrackd -e

While trigering fail-overs, you should see the same states in the
active's internal cache and the backup's external cache. If that does
happen, there's a problem somewhere.

I'm about to release 0.9.11 but before I'd like to close pending issues.

The issue is solved by adding "conntrackd -B" to my script. According to the logs, such instruction sends bulk update. What is it for exactly ?

It forces the new primary to send a bulk update with the current state (that has been injected into the kernel) to the backup. You were using heartbeat? It seems that heartbeat triggers the backup state transition (thus, the request to resync to the new primary) before the new primary is itself in sync.

BTW, this change in the primary-backup.sh script has been already included in the conntrack-tools 0.9.11 (that I release a couple of days ago).

In fact, I'm using Heartbeat2 and that's one major difference between our two test beds.

Again, many thanks for your assistance and your great work Pablo !

Best regards,
begin:vcard
fn:Yoann Juet
n:Juet;Yoann
org;quoted-printable:;DSI Universit=C3=A9 de Nantes
adr;quoted-printable:BP92208;;2, rue de la Houssini=C3=A8re;Nantes;;44322;France
email;internet:yoann.juet@xxxxxxxxxxxxxx
title;quoted-printable:Ing=C3=A9nieur s=C3=A9curit=C3=A9 & r=C3=A9seau
tel;work:02.51.12.53.93
tel;fax:02.51.12.58.60
x-mozilla-html:FALSE
version:2.1
end:vcard


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux