Red Hat Training

A Red Hat training course is available for Red Hat Enterprise Linux

1.4.2. 直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​

建​​​​​​​立​​​​​​​使​​​​​​​用​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​的​​​​​​​ LVS 设​​​​​​​置​​​​​​​和​​​​​​​其​​​​​​​它​​​​​​​ LVS 联​​​​​​​网​​​​​​​布​​​​​​​局​​​​​​​相​​​​​​​比​​​​​​​有​​​​​​​更​​​​​​​好​​​​​​​的​​​​​​​性​​​​​​​能​​​​​​​。​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​允​​​​​​​许​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​将​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​直​​​​​​​接​​​​​​​处​​​​​​​理​​​​​​​并​​​​​​​路​​​​​​​由​​​​​​​到​​​​​​​发​​​​​​​出​​​​​​​请​​​​​​​求​​​​​​​的​​​​​​​用​​​​​​​户​​​​​​​,而​​​​​​​不​​​​​​​是​​​​​​​将​​​​​​​所​​​​​​​有​​​​​​​外​​​​​​​发​​​​​​​的​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​通​​​​​​​过​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​发​​​​​​​送​​​​​​​给​​​​​​​用​​​​​​​户​​​​​​​。​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​通​​​​​​​过​​​​​​​将​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​的​​​​​​​任​​​​​​​务​​​​​​​变​​​​​​​为​​​​​​​仅​​​​​​​仅​​​​​​​处​​​​​​​理​​​​​​​进​​​​​​​入​​​​​​​的​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​,从​​​​​​​而​​​​​​​降​​​​​​​低​​​​​​​了​​​​​​​出​​​​​​​现​​​​​​​网​​​​​​​络​​​​​​​性​​​​​​​能​​​​​​​问​​​​​​​题​​​​​​​的​​​​​​​可​​​​​​​能​​​​​​​性​​​​​​​。​​​​​​​
LVS Implemented with Direct Routing

图 1.4. LVS Implemented with Direct Routing

在​​​​​​​典​​​​​​​型​​​​​​​的​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​设​​​​​​​置​​​​​​​中​​​​​​​,LVS 路​​​​​​​由​​​​​​​器​​​​​​​通​​​​​​​过​​​​​​​虚​​​​​​​拟​​​​​​​ IP(VIP)接​​​​​​​收​​​​​​​进​​​​​​​入​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​的​​​​​​​请​​​​​​​求​​​​​​​,使​​​​​​​用​​​​​​​调​​​​​​​度​​​​​​​算​​​​​​​法​​​​​​​将​​​​​​​请​​​​​​​求​​​​​​​路​​​​​​​由​​​​​​​到​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​中​​​​​​​。​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​会​​​​​​​处​​​​​​​理​​​​​​​这​​​​​​​些​​​​​​​请​​​​​​​求​​​​​​​,并​​​​​​​将​​​​​​​回​​​​​​​复​​​​​​​绕​​​​​​​过​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​直​​​​​​​接​​​​​​​发​​​​​​​送​​​​​​​给​​​​​​​客​​​​​​​户​​​​​​​端​​​​​​​。​​​​​​​这​​​​​​​种​​​​​​​路​​​​​​​由​​​​​​​方​​​​​​​法​​​​​​​允​​​​​​​许​​​​​​​在​​​​​​​不​​​​​​​增​​​​​​​加​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​将​​​​​​​外​​​​​​​发​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​从​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​路​​​​​​​由​​​​​​​到​​​​​​​客​​​​​​​户​​​​​​​端​​​​​​​负​​​​​​​担​​​​​​​的​​​​​​​情​​​​​​​况​​​​​​​下​​​​​​​添​​​​​​​加​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​的​​​​​​​能​​​​​​​力​​​​​​​,以​​​​​​​免​​​​​​​在​​​​​​​网​​​​​​​络​​​​​​​负​​​​​​​载​​​​​​​较​​​​​​​重​​​​​​​的​​​​​​​情​​​​​​​况​​​​​​​下​​​​​​​形​​​​​​​成​​​​​​​瓶​​​​​​​颈​​​​​​​。​​​​​​​

1.4.2.1. 直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​和​​​​​​​ ARP 限​​​​​​​制​​​​​​​

虽​​​​​​​然​​​​​​​在​​​​​​​ LVS 中​​​​​​​使​​​​​​​用​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​有​​​​​​​很​​​​​​​多​​​​​​​优​​​​​​​点​​​​​​​,但​​​​​​​也​​​​​​​有​​​​​​​一​​​​​​​些​​​​​​​局​​​​​​​限​​​​​​​。​​​​​​​LVS 使​​​​​​​用​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​最​​​​​​​常​​​​​​​见​​​​​​​的​​​​​​​问​​​​​​​题​​​​​​​就​​​​​​​出​​​​​​​现​​​​​​​在​​​​​​​地​​​​​​​址​​​​​​​解​​​​​​​析​​​​​​​协​​​​​​​议​​​​​​​ARP)。​​​​​​​
In typical situations, a client on the Internet sends a request to an IP address. Network routers typically send requests to their destination by relating IP addresses to a machine's MAC address with ARP. ARP requests are broadcast to all connected machines on a network, and the machine with the correct IP/MAC address combination receives the packet. The IP/MAC associations are stored in an ARP cache, which is cleared periodically (usually every 15 minutes) and refilled with IP/MAC associations.
在​​​​​​​直​​​​​​​接​​​​​​​路​​​​​​​由​​​​​​​ LVS 设​​​​​​​置​​​​​​​中​​​​​​​出​​​​​​​现​​​​​​​ ARP 请​​​​​​​求​​​​​​​问​​​​​​​题​​​​​​​就​​​​​​​是​​​​​​​因​​​​​​​为​​​​​​​客​​​​​​​户​​​​​​​端​​​​​​​对​​​​​​​某​​​​​​​个​​​​​​​ IP 地​​​​​​​址​​​​​​​的​​​​​​​请​​​​​​​求​​​​​​​必​​​​​​​须​​​​​​​与​​​​​​​要​​​​​​​处​​​​​​​理​​​​​​​请​​​​​​​求​​​​​​​的​​​​​​​ MAC 地​​​​​​​址​​​​​​​关​​​​​​​联​​​​​​​,LVS系​​​​​​​统​​​​​​​的​​​​​​​虚​​​​​​​拟​​​​​​​ IP 地​​​​​​​址​​​​​​​也​​​​​​​必​​​​​​​须​​​​​​​与​​​​​​​ MAC 关​​​​​​​联​​​​​​​。​​​​​​​但​​​​​​​由​​​​​​​于​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​和​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​有​​​​​​​相​​​​​​​同​​​​​​​的​​​​​​​ VIP,因​​​​​​​此​​​​​​​ ARP 请​​​​​​​求​​​​​​​会​​​​​​​被​​​​​​​广​​​​​​​播​​​​​​​到​​​​​​​与​​​​​​​该​​​​​​​ VIP 关​​​​​​​联​​​​​​​的​​​​​​​所​​​​​​​机​​​​​​​器​​​​​​​。​​​​​​​这​​​​​​​会​​​​​​​引​​​​​​​发​​​​​​​一​​​​​​​些​​​​​​​问​​​​​​​题​​​​​​​,比​​​​​​​如​​​​​​​完​​​​​​​全​​​​​​​绕​​​​​​​过​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​将​​​​​​​ VIP 直​​​​​​​接​​​​​​​关​​​​​​​联​​​​​​​到​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​之​​​​​​​一​​​​​​​并​​​​​​​直​​​​​​​接​​​​​​​处​​​​​​​理​​​​​​​请​​​​​​​求​​​​​​​,与​​​​​​​设​​​​​​​置​​​​​​​ LVS 的​​​​​​​初​​​​​​​衷​​​​​​​项​​​​​​​背​​​​​​​。​​​​​​​
要​​​​​​​解​​​​​​​决​​​​​​​这​​​​​​​个​​​​​​​问​​​​​​​题​​​​​​​,请​​​​​​​确​​​​​​​定​​​​​​​总​​​​​​​是​​​​​​​将​​​​​​​进​​​​​​​入​​​​​​​请​​​​​​​求​​​​​​​发​​​​​​​送​​​​​​​到​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​,而​​​​​​​不​​​​​​​是​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​。​​​​​​​使​​​​​​​用​​​​​​​ arptables_jf 或​​​​​​​者​​​​​​​ iptables 数​​​​​​​据​​​​​​​包​​​​​​​过​​​​​​​滤​​​​​​​工​​​​​​​具​​​​​​​即​​​​​​​可​​​​​​​达​​​​​​​到​​​​​​​此​​​​​​​目​​​​​​​的​​​​​​​,理​​​​​​​由​​​​​​​如​​​​​​​下​​​​​​​:
  • arptables_jf 可​​​​​​​防​​​​​​​止​​​​​​​ ARP 将​​​​​​​ VIP 与​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​关​​​​​​​联​​​​​​​。​​​​​​​
  • iptables 方​​​​​​​法​​​​​​​完​​​​​​​全​​​​​​​避​​​​​​​免​​​​​​​了​​​​​​​ ARP 问​​​​​​​题​​​​​​​,因​​​​​​​为​​​​​​​它​​​​​​​从​​​​​​​来​​​​​​​没​​​​​​​有​​​​​​​在​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​中​​​​​​​配​​​​​​​置​​​​​​​ VIP。​​​​​​​