Re: HA firewall providing "masquerade": SNAT the only way to go?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 29.08.19 10:02, Laura Garcia wrote:

> The target CLUSTERIP can be used for active/active. Check it out.
> 


Hi Laura,
Thanks for your reply, but I can not yet get everything together in my
head...

I do not get how CLUSTERIP and SNAT can be combined or play together.

I see CLUSTERIP can be used, or is used for INPUT to load-balance a
destination, which terminates on the device itself.

* Neither the multicast MAC, nor the cluster IP is assigned to the
interface with iproute2
* The multicast mac and ip is only stated in the CLUSTERIP rule
* netfilter handels arp and route filter

Is it possible to have one rule with CLUSTERIP and -d 0.0.0.0 and
afterwards a SNAT rule with the source of the vIP?

Bernd



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux