netdev
[Top] [All Lists]

Re: [PATCH 2.6] iptables CLUSTERIP target, seq_file version

To: jamal <hadi@xxxxxxxxxx>
Subject: Re: [PATCH 2.6] iptables CLUSTERIP target, seq_file version
From: Harald Welte <laforge@xxxxxxxxxxxxx>
Date: Thu, 21 Oct 2004 20:03:24 +0200
Cc: "David S. Miller" <davem@xxxxxxxxxxxxx>, Linux Netdev List <netdev@xxxxxxxxxxx>, Netfilter Development Mailinglist <netfilter-devel@xxxxxxxxxxxxxxxxxxx>, lmb@xxxxxxx
In-reply-to: <1098380650.1031.82.camel@jzny.localdomain>
Mail-followup-to: Harald Welte <laforge@xxxxxxxxxxxxx>, jamal <hadi@xxxxxxxxxx>, "David S. Miller" <davem@xxxxxxxxxxxxx>, Linux Netdev List <netdev@xxxxxxxxxxx>, Netfilter Development Mailinglist <netfilter-devel@xxxxxxxxxxxxxxxxxxx>, lmb@xxxxxxx
References: <20041020223828.GP19899@sunbeam.de.gnumonks.org> <20041021163655.GK3551@sunbeam.de.gnumonks.org> <1098380650.1031.82.camel@jzny.localdomain>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mutt/1.5.6+20040907i
On Thu, Oct 21, 2004 at 01:44:11PM -0400, jamal wrote:
> 
> Sorry, couldnt resist - so out of hiding for just a few seconds; should
> be able to achieve this much simpler with gact.

One of the issues that CLUSTERIP needed to do is to work with
locally-originated connections, i.e. every node within the cluster still
has to be able to open tcp connections to anywhere.

We currently catch this with connection tracking, which will assign all
reply packets to such outbound connections INVALID on all but the
originating node in the cluster.

Yes, I know, this sounds like a very strange setup.  Still it was one of
the requirements for it's implementation.

-- 
- Harald Welte <laforge@xxxxxxxxxxxxx>             http://www.netfilter.org/
============================================================================
  "Fragmentation is like classful addressing -- an interesting early
   architectural error that shows how much experimentation was going
   on while IP was being designed."                    -- Paul Vixie

Attachment: signature.asc
Description: Digital signature

<Prev in Thread] Current Thread [Next in Thread>