Red Hat Training

A Red Hat training course is available for Red Hat Enterprise Linux

1.8.3.2. 直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​

和​​​​​​​ NAT 相​​​​​​​比​​​​​​​,直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​可​​​​​​​以​​​​​​​提​​​​​​​供​​​​​​​增​​​​​​​强​​​​​​​的​​​​​​​性​​​​​​​能​​​​​​​。​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​允​​​​​​​许​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​处​​​​​​​理​​​​​​​和​​​​​​​直​​​​​​​接​​​​​​​发​​​​​​​送​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​给​​​​​​​请​​​​​​​求​​​​​​​用​​​​​​​户​​​​​​​而​​​​​​​不​​​​​​​是​​​​​​​通​​​​​​​过​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​传​​​​​​​送​​​​​​​转​​​​​​​出​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​。​​​​​​​让​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​只​​​​​​​处​​​​​​​理​​​​​​​转​​​​​​​入​​​​​​​的​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​,直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​降​​​​​​​低​​​​​​​了​​​​​​​网​​​​​​​络​​​​​​​性​​​​​​​能​​​​​​​出​​​​​​​现​​​​​​​问​​​​​​​题​​​​​​​的​​​​​​​可​​​​​​​能​​​​​​​性​​​​​​​。​​​​​​​
LVS Implemented with Direct Routing

图 1.23. LVS Implemented with Direct Routing

在​​​​​​​典​​​​​​​型​​​​​​​的​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​ LVS 配​​​​​​​置​​​​​​​里​​​​​​​,LVS 路​​​​​​​由​​​​​​​器​​​​​​​通​​​​​​​过​​​​​​​虚​​​​​​​拟​​​​​​​ IP(VIP)接​​​​​​​收​​​​​​​转​​​​​​​入​​​​​​​的​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​请​​​​​​​求​​​​​​​并​​​​​​​使​​​​​​​用​​​​​​​一​​​​​​​个​​​​​​​调​​​​​​​度​​​​​​​算​​​​​​​法​​​​​​​来​​​​​​​将​​​​​​​请​​​​​​​求​​​​​​​发​​​​​​​送​​​​​​​到​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​上​​​​​​​。​​​​​​​每​​​​​​​个​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​都​​​​​​​处​​​​​​​理​​​​​​​请​​​​​​​求​​​​​​​,并​​​​​​​将​​​​​​​响​​​​​​​应​​​​​​​直​​​​​​​接​​​​​​​发​​​​​​​送​​​​​​​给​​​​​​​客​​​​​​​户​​​​​​​而​​​​​​​不​​​​​​​通​​​​​​​过​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​。​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​提​​​​​​​供​​​​​​​了​​​​​​​可​​​​​​​伸​​​​​​​缩​​​​​​​性​​​​​​​,因​​​​​​​为​​​​​​​可​​​​​​​以​​​​​​​添​​​​​​​加​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​而​​​​​​​不​​​​​​​增​​​​​​​加​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​将​​​​​​​转​​​​​​​出​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​从​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​发​​​​​​​送​​​​​​​给​​​​​​​客​​​​​​​户​​​​​​​的​​​​​​​负​​​​​​​担​​​​​​​,而​​​​​​​这​​​​​​​在​​​​​​​网​​​​​​​络​​​​​​​负​​​​​​​载​​​​​​​很​​​​​​​重​​​​​​​时​​​​​​​可​​​​​​​能​​​​​​​是​​​​​​​瓶​​​​​​​颈​​​​​​​。​​​​​​​
虽​​​​​​​然​​​​​​​在​​​​​​​ LVS 里​​​​​​​使​​​​​​​用​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​有​​​​​​​很​​​​​​​多​​​​​​​优​​​​​​​点​​​​​​​,但​​​​​​​它​​​​​​​也​​​​​​​有​​​​​​​缺​​​​​​​陷​​​​​​​。​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​最​​​​​​​常​​​​​​​见​​​​​​​的​​​​​​​问​​​​​​​题​​​​​​​是​​​​​​​和​​​​​​​ 地​​​​​​​址​​​​​​​解​​​​​​​析​​​​​​​协​​​​​​​议​​​​​​​(Address Resolution Protocol)ARP)相​​​​​​​关​​​​​​​的​​​​​​​。​​​​​​​
In typical situations, a client on the Internet sends a request to an IP address. Network routers typically send requests to their destination by relating IP addresses to a machine's MAC address with ARP. ARP requests are broadcast to all connected machines on a network, and the machine with the correct IP/MAC address combination receives the packet. The IP/MAC associations are stored in an ARP cache, which is cleared periodically (usually every 15 minutes) and refilled with IP/MAC associations.
使​​​​​​​用​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​的​​​​​​​ LVS 配​​​​​​​置​​​​​​​里​​​​​​​和​​​​​​​ ARP 请​​​​​​​求​​​​​​​相​​​​​​​关​​​​​​​的​​​​​​​问​​​​​​​题​​​​​​​是​​​​​​​:因​​​​​​​为​​​​​​​到​​​​​​​一​​​​​​​个​​​​​​​ IP 地​​​​​​​址​​​​​​​的​​​​​​​客​​​​​​​户​​​​​​​请​​​​​​​求​​​​​​​必​​​​​​​须​​​​​​​和​​​​​​​一​​​​​​​个​​​​​​​ MAC 地​​​​​​​址​​​​​​​相​​​​​​​关​​​​​​​联​​​​​​​才​​​​​​​能​​​​​​​被​​​​​​​处​​​​​​​理​​​​​​​,LVS 路​​​​​​​由​​​​​​​器​​​​​​​的​​​​​​​虚​​​​​​​拟​​​​​​​ IP 地​​​​​​​址​​​​​​​也​​​​​​​必​​​​​​​须​​​​​​​关​​​​​​​联​​​​​​​到​​​​​​​一​​​​​​​个​​​​​​​ MAC。​​​​​​​然​​​​​​​而​​​​​​​,因​​​​​​​为​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​和​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​具​​​​​​​有​​​​​​​相​​​​​​​同​​​​​​​的​​​​​​​ VIP,ARP 请​​​​​​​求​​​​​​​被​​​​​​​广​​​​​​​播​​​​​​​至​​​​​​​和​​​​​​​这​​​​​​​个​​​​​​​ VIP 相​​​​​​​关​​​​​​​联​​​​​​​的​​​​​​​所​​​​​​​有​​​​​​​节​​​​​​​点​​​​​​​。​​​​​​​这​​​​​​​会​​​​​​​导​​​​​​​致​​​​​​​几​​​​​​​个​​​​​​​问​​​​​​​题​​​​​​​,如​​​​​​​直​​​​​​​接​​​​​​​和​​​​​​​某​​​​​​​个​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​相​​​​​​​关​​​​​​​联​​​​​​​或​​​​​​​直​​​​​​​接​​​​​​​处​​​​​​​理​​​​​​​请​​​​​​​求​​​​​​​的​​​​​​​ VIP,将​​​​​​​完​​​​​​​全​​​​​​​绕​​​​​​​过​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​并​​​​​​​使​​​​​​​ LVS 配​​​​​​​置​​​​​​​不​​​​​​​起​​​​​​​作​​​​​​​用​​​​​​​。​​​​​​​即​​​​​​​使​​​​​​​是​​​​​​​带​​​​​​​有​​​​​​​强​​​​​​​大​​​​​​​的​​​​​​​ CPU、​​​​​​​可​​​​​​​以​​​​​​​快​​​​​​​速​​​​​​​响​​​​​​​应​​​​​​​客​​​​​​​户​​​​​​​请​​​​​​​求​​​​​​​的​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​也​​​​​​​未​​​​​​​必​​​​​​​能​​​​​​​解​​​​​​​决​​​​​​​这​​​​​​​个​​​​​​​问​​​​​​​题​​​​​​​。​​​​​​​如​​​​​​​果​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​负​​​​​​​载​​​​​​​很​​​​​​​重​​​​​​​,它​​​​​​​对​​​​​​​ ARP 的​​​​​​​响​​​​​​​应​​​​​​​可​​​​​​​能​​​​​​​会​​​​​​​比​​​​​​​较​​​​​​​空​​​​​​​闲​​​​​​​的​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​更​​​​​​​慢​​​​​​​,后​​​​​​​者​​​​​​​分​​​​​​​配​​​​​​​了​​​​​​​请​​​​​​​求​​​​​​​客​​​​​​​户​​​​​​​的​​​​​​​ ARP 缓​​​​​​​存​​​​​​​里​​​​​​​的​​​​​​​ VIP 且​​​​​​​响​​​​​​​应​​​​​​​更​​​​​​​快​​​​​​​。​​​​​​​
要​​​​​​​解​​​​​​​决​​​​​​​这​​​​​​​个​​​​​​​问​​​​​​​题​​​​​​​,转​​​​​​​入​​​​​​​的​​​​​​​请​​​​​​​求​​​​​​​应​​​​​​​该​​​​​​​只​​​​​​​和​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​的​​​​​​​ VIP 相​​​​​​​关​​​​​​​联​​​​​​​,这​​​​​​​样​​​​​​​就​​​​​​​会​​​​​​​正​​​​​​​确​​​​​​​地​​​​​​​处​​​​​​​理​​​​​​​请​​​​​​​求​​​​​​​并​​​​​​​将​​​​​​​它​​​​​​​们​​​​​​​发​​​​​​​送​​​​​​​到​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​池​​​​​​​。​​​​​​​这​​​​​​​可​​​​​​​以​​​​​​​用​​​​​​​ arptables 数​​​​​​​据​​​​​​​包​​​​​​​过​​​​​​​滤​​​​​​​工​​​​​​​具​​​​​​​来​​​​​​​实​​​​​​​现​​​​​​​。​​​​​​​