Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Linux Virtual Server: Users

[lvs-users] netfilter match for ipvs connections

 

 

Linux Virtual Server users RSS feed   Index | Next | Previous | View Threaded


windo at p6drad-teel

Apr 15, 2008, 11:08 PM

Post #1 of 3 (431 views)
Permalink
[lvs-users] netfilter match for ipvs connections

Yo!

I'll ask again, as I think someone might yet have an opinion on this:

Would it make sense in having a netfilter match that would look up
connections on ipvs connection table? That would allow for filtering
outbound packets in FORWARD without having to export the connections to
conntrack and for a more consistent action as the outbound check would
be the same as the inbound check (based on ipvs knowledge of the
connection).

And also, are there maybe peculiarities of ipvs connection tables that
would make this infeasible? I'd be willing to look into it, if there was
some opinion of it making sense.

Siim


_______________________________________________
LinuxVirtualServer.org mailing list - lvs-users[at]LinuxVirtualServer.org
Send requests to lvs-users-request[at]LinuxVirtualServer.org
or go to http://lists.graemef.net/mailman/listinfo/lvs-users


jmack at wm7d

Apr 16, 2008, 7:42 AM

Post #2 of 3 (405 views)
Permalink
Re: [lvs-users] include config [In reply to]

> How about ldirectord? I know I for one would appreciate that feature.

The best way to have this happen would be to code it up and
send the patch to Horms

Joe
--
Joseph Mack NA3T EME(B,D), FM05lw North Carolina
jmack (at) wm7d (dot) net - azimuthal equidistant map
generator at http://www.wm7d.net/azproj.shtml
Homepage http://www.austintek.com/ It's GNU/Linux!

_______________________________________________
LinuxVirtualServer.org mailing list - lvs-users[at]LinuxVirtualServer.org
Send requests to lvs-users-request[at]LinuxVirtualServer.org
or go to http://lists.graemef.net/mailman/listinfo/lvs-users


bgs at bgs

Apr 21, 2008, 1:07 AM

Post #3 of 3 (369 views)
Permalink
Re: [lvs-users] netfilter match for ipvs connections [In reply to]

Hi,

What is it you really want to achieve?

Inbound should be allowed through (that's why you set up lvs in the
first place). If you want to block outbound connections you can do it
even without conntrack by blocking outbound SYNs.

Regards
Bgs


Siim Põder wrote:
> Yo!
>
> I'll ask again, as I think someone might yet have an opinion on this:
>
> Would it make sense in having a netfilter match that would look up
> connections on ipvs connection table? That would allow for filtering
> outbound packets in FORWARD without having to export the connections to
> conntrack and for a more consistent action as the outbound check would
> be the same as the inbound check (based on ipvs knowledge of the
> connection).
>
> And also, are there maybe peculiarities of ipvs connection tables that
> would make this infeasible? I'd be willing to look into it, if there was
> some opinion of it making sense.
>
> Siim
>
>
> _______________________________________________
> LinuxVirtualServer.org mailing list - lvs-users[at]LinuxVirtualServer.org
> Send requests to lvs-users-request[at]LinuxVirtualServer.org
> or go to http://lists.graemef.net/mailman/listinfo/lvs-users
>

_______________________________________________
LinuxVirtualServer.org mailing list - lvs-users[at]LinuxVirtualServer.org
Send requests to lvs-users-request[at]LinuxVirtualServer.org
or go to http://lists.graemef.net/mailman/listinfo/lvs-users

Linux Virtual Server users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.