Use Virtual interface ( eri0:1 ) ip as source address - spoofing ?

From: Laurence Moughan (Laurence.Moughan@aerlingus.com)
Date: Thu Jun 16 2005 - 10:16:51 EDT


Hi All,

I have an ftp server ftp1 on say 10.0.0.10 behind a firewall being
natted to say 192.0.0.10

interface eri0

i want to cluster the ftp server with a partner ( using opensource
software heartbeat ) this provides a virtual ip on the cative node,

so we will then have machines

ftp1 real ip address 10.0.0.1 interface eri0
ftp2 real address 10.0.0.2 interface er10

a virtual ip floating between the machines on a virtual eri interface
on one at ip 10.0.0.10 eri0:1( up on the active node )

Now this is obviously going to break my firewall rules as the source of
outgoing packets wil now be the ftp servers real address 10.0.0.1 or
10.0.0.2

so

is there a way to foce all outbound packets to go from the virtual
interface ( eri0:1 ) address 10.0.0.10 ?

Thanks

laurence

..For low fares and great deals on hotels, car hire and travel insurance visit http://www.aerlingus.com
of any action in reliance upon, this information by persons or entities
other than the intended recipient is prohibited.If you have received
this email in error please notify the sender immediately and delete
the material.
*******************************************************************************
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:30:54 EDT