From: Edmundo Carmona <eantoranz@gmail.com>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: netfilter@lists.netfilter.org
Subject: Re: is this the zillionth mail asking for this detail?
Date: Thu, 21 Jul 2005 10:06:26 -0400 [thread overview]
Message-ID: <65aa6af905072107063ebab0bc@mail.gmail.com> (raw)
In-Reply-To: <Pine.LNX.4.58.0507211523100.27131@blackhole.kfki.hu>
I'm jumping on one leg! Forgive me if I don't sound serious right now.
Yeah... no service on the firewall, right? :-) That's absolutely not
the case of this particular firewall. Not like I have a networking lab
in the firewall... but there's squid and VPN (at least).
I want to make sure I got it right:
Suppose I have three internet connections.
I will load-balance two of them and leave one out just for VPN
connections and other services. According to what you are saying, I
could mark the packets in mangle-output that come from the VPN service
and then force them to go out with a rule that uses that firewall
mark.... right?
Thank you very much for your feedback!
Note:
It's not like I'm freaky and I just want to load balance two of them
leaving one out. I COUDLN'T get to load balance all three. After some
experimentation I noticed that two of the interfaces didn't get along
very well to make a multipath routing. I think it's because they're
both on the same network. Maybe you know of some multipath guru that
could help me with this so I can load-balance all of them.
On 7/21/05, Jozsef Kadlecsik <kadlec@blackhole.kfki.hu> wrote:
> On Thu, 21 Jul 2005, Jan Engelhardt wrote:
>
> > >local process -> routing -> OUTPUT chain -> routing -> POSTROUTING chain
> > >
> > >No problem with policy routing for the locally generated traffic.
> >
> > This sounds like a total overhead calculating the route twice.
>
> The first one is required to fill out output device for the packet. The
> second one is there to give chance to play with routing in OUTPUT.
>
> This is traffic, generated locally, on the firewall.
> You should run nothing on your firewall ;-)
>
> Best regards,
> Jozsef
> -
> E-mail : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu
> PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
> Address : KFKI Research Institute for Particle and Nuclear Physics
> H-1525 Budapest 114, POB. 49, Hungary
>
>
next prev parent reply other threads:[~2005-07-21 14:06 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-07-21 4:50 is this the zillionth mail asking for this detail? Edmundo Carmona
2005-07-21 11:23 ` /dev/rob0
2005-07-21 13:15 ` Jozsef Kadlecsik
2005-07-21 13:21 ` Jan Engelhardt
2005-07-21 13:27 ` Jozsef Kadlecsik
2005-07-21 13:53 ` Jörg Harmuth
2005-07-21 14:02 ` Jozsef Kadlecsik
2005-07-21 14:09 ` Edmundo Carmona
2005-08-10 15:37 ` Edmundo Carmona
2005-08-10 20:06 ` Jozsef Kadlecsik
2005-08-10 20:11 ` /dev/rob0
2005-08-11 15:06 ` Edmundo Carmona
2005-08-11 5:57 ` Jan Engelhardt
2005-07-21 14:06 ` Edmundo Carmona [this message]
2005-07-21 14:15 ` Jan Engelhardt
[not found] ` <65aa6af9050721071866e3c73b@mail.gmail.com>
[not found] ` <Pine.LNX.4.61.0507211650020.23894@yvahk01.tjqt.qr>
2005-07-21 15:04 ` Edmundo Carmona
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=65aa6af905072107063ebab0bc@mail.gmail.com \
--to=eantoranz@gmail.com \
--cc=kadlec@blackhole.kfki.hu \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.