From: Edmundo Carmona <eantoranz@gmail.com>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: netfilter@lists.netfilter.org
Subject: Re: is this the zillionth mail asking for this detail?
Date: Thu, 21 Jul 2005 10:06:26 -0400 [thread overview]
Message-ID: <65aa6af905072107063ebab0bc@mail.gmail.com> (raw)
In-Reply-To: <Pine.LNX.4.58.0507211523100.27131@blackhole.kfki.hu>
I'm jumping on one leg! Forgive me if I don't sound serious right now.
Yeah... no service on the firewall, right? :-) That's absolutely not
the case of this particular firewall. Not like I have a networking lab
in the firewall... but there's squid and VPN (at least).
I want to make sure I got it right:
Suppose I have three internet connections.
I will load-balance two of them and leave one out just for VPN
connections and other services. According to what you are saying, I
could mark the packets in mangle-output that come from the VPN service
and then force them to go out with a rule that uses that firewall
mark.... right?
Thank you very much for your feedback!
Note:
It's not like I'm freaky and I just want to load balance two of them
leaving one out. I COUDLN'T get to load balance all three. After some
experimentation I noticed that two of the interfaces didn't get along
very well to make a multipath routing. I think it's because they're
both on the same network. Maybe you know of some multipath guru that
could help me with this so I can load-balance all of them.
On 7/21/05, Jozsef Kadlecsik <kadlec@blackhole.kfki.hu> wrote:
> On Thu, 21 Jul 2005, Jan Engelhardt wrote:
>
> > >local process -> routing -> OUTPUT chain -> routing -> POSTROUTING chain
> > >
> > >No problem with policy routing for the locally generated traffic.
> >
> > This sounds like a total overhead calculating the route twice.
>
> The first one is required to fill out output device for the packet. The
> second one is there to give chance to play with routing in OUTPUT.
>
> This is traffic, generated locally, on the firewall.
> You should run nothing on your firewall ;-)
>
> Best regards,
> Jozsef
> -
> E-mail : kadlec@blackhole.kfki.hu, kadlec@sunserv.kfki.hu
> PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
> Address : KFKI Research Institute for Particle and Nuclear Physics
> H-1525 Budapest 114, POB. 49, Hungary
>
>
next prev parent reply other threads:[~2005-07-21 14:06 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-07-21 4:50 is this the zillionth mail asking for this detail? Edmundo Carmona
2005-07-21 11:23 ` /dev/rob0
2005-07-21 13:15 ` Jozsef Kadlecsik
2005-07-21 13:21 ` Jan Engelhardt
2005-07-21 13:27 ` Jozsef Kadlecsik
2005-07-21 13:53 ` Jörg Harmuth
2005-07-21 14:02 ` Jozsef Kadlecsik
2005-07-21 14:09 ` Edmundo Carmona
2005-08-10 15:37 ` Edmundo Carmona
2005-08-10 20:06 ` Jozsef Kadlecsik
2005-08-10 20:11 ` /dev/rob0
2005-08-11 15:06 ` Edmundo Carmona
2005-08-11 5:57 ` Jan Engelhardt
2005-07-21 14:06 ` Edmundo Carmona [this message]
2005-07-21 14:15 ` Jan Engelhardt
[not found] ` <65aa6af9050721071866e3c73b@mail.gmail.com>
[not found] ` <Pine.LNX.4.61.0507211650020.23894@yvahk01.tjqt.qr>
2005-07-21 15:04 ` Edmundo Carmona
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=65aa6af905072107063ebab0bc@mail.gmail.com \
--to=eantoranz@gmail.com \
--cc=kadlec@blackhole.kfki.hu \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox