Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Edmundo Carmona <eantoranz@gmail.com>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: netfilter@lists.netfilter.org
Subject: Re: is this the zillionth mail asking for this detail?
Date: Thu, 21 Jul 2005 10:06:26 -0400	[thread overview]
Message-ID: <65aa6af905072107063ebab0bc@mail.gmail.com> (raw)
In-Reply-To: <Pine.LNX.4.58.0507211523100.27131@blackhole.kfki.hu>

I'm jumping on one leg! Forgive me if I don't sound serious right now.

Yeah... no service on the firewall, right? :-) That's absolutely not
the case of this particular firewall. Not like I have a networking lab
in the firewall... but there's squid and VPN (at least).

I want to make sure I got it right:

Suppose I have three internet connections.

I will load-balance two of them and leave one out just for VPN
connections and other services. According to what you are saying, I
could mark the packets in mangle-output that come from the VPN service
and then force them to go out with a rule that uses that firewall
mark.... right?

Thank you very much for your feedback!

Note:
It's not like I'm freaky and I just want to load balance two of them
leaving one out. I COUDLN'T get to load balance all three. After some
experimentation I noticed that two of the interfaces didn't get along
very well to make a multipath routing. I think it's because they're
both on the same network. Maybe you know of some multipath guru that
could help me with this so I can load-balance all of them.



On 7/21/05, Jozsef Kadlecsik <kadlec@blackhole.kfki.hu> wrote:
> On Thu, 21 Jul 2005, Jan Engelhardt wrote:
> 
> > >local process -> routing -> OUTPUT chain -> routing -> POSTROUTING chain
> > >
> > >No problem with policy routing for the locally generated traffic.
> >
> > This sounds like a total overhead calculating the route twice.
> 
> The first one is required to fill out output device for the packet. The
> second one is there to give chance to play with routing in OUTPUT.
> 
> This is traffic, generated locally, on the firewall.
> You should run nothing on your firewall ;-)
> 
> Best regards,
> Jozsef
> -
> E-mail  : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu
> PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
> Address : KFKI Research Institute for Particle and Nuclear Physics
>           H-1525 Budapest 114, POB. 49, Hungary
> 
>


  parent reply	other threads:[~2005-07-21 14:06 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-07-21  4:50 is this the zillionth mail asking for this detail? Edmundo Carmona
2005-07-21 11:23 ` /dev/rob0
2005-07-21 13:15   ` Jozsef Kadlecsik
2005-07-21 13:21     ` Jan Engelhardt
2005-07-21 13:27       ` Jozsef Kadlecsik
2005-07-21 13:53         ` Jörg Harmuth
2005-07-21 14:02           ` Jozsef Kadlecsik
2005-07-21 14:09             ` Edmundo Carmona
2005-08-10 15:37               ` Edmundo Carmona
2005-08-10 20:06                 ` Jozsef Kadlecsik
2005-08-10 20:11                 ` /dev/rob0
2005-08-11 15:06                   ` Edmundo Carmona
2005-08-11  5:57                 ` Jan Engelhardt
2005-07-21 14:06         ` Edmundo Carmona [this message]
2005-07-21 14:15           ` Jan Engelhardt
     [not found]             ` <65aa6af9050721071866e3c73b@mail.gmail.com>
     [not found]               ` <Pine.LNX.4.61.0507211650020.23894@yvahk01.tjqt.qr>
2005-07-21 15:04                 ` Edmundo Carmona

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=65aa6af905072107063ebab0bc@mail.gmail.com \
    --to=eantoranz@gmail.com \
    --cc=kadlec@blackhole.kfki.hu \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox