The previous article has explained that the principle of LVS has worked, and Dr Mode and Nat mode are different in deployment:
650) this.width=650; "src=" Http://s5.51cto.com/wyfs02/M02/78/3F/wKiom1Z42zOBJOvgAAArIY30z-M057.png "title=" 1.png " alt= "Wkiom1z42zobjovgaaariy30z-m057.png"/> In this topology, the scheduler serves as a portal for users to access the Web, and each Web response is directly based on the network and does not respond through the scheduler.
There are several points to note when deploying the LVS environment for Dr Mode:
The dispatcher and each node must have a VIP address configured
- The
-
Scheduler turns off ICMP redirection (icmp The redirect message is one of the icmp re-select route some attacks using Icmp ICMP redirect package to make the host inaccessible or initiate DDoS to a host
The node server adjusts the ARP response ( adjusts the kernel's arp response parameters to prevent updates to the VIP 's MAC address to avoid conflicts )
Add VIP local access routes to the node server
Configuration process:
1. Scheduler Loading LVS Module
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/78/3F/wKiom1Z43Taz3hE0AAAKUDmtB8U502.png "style=" float: none; "title=" 2.png "alt=" Wkiom1z43taz3he0aaakudmtb8u502.png "/>
2. Installing the IPVSADM management tool
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/78/3E/wKioL1Z43UiCtV48AAAP8biUujw322.png "style=" float: none; "title=" 3.png "alt=" Wkiol1z43uictv48aaap8biuujw322.png "/>
3. Configure the VIP address of the Scheduler
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/78/3F/wKiom1Z43TaxC7KmAAAj2dVmb1g688.png "style=" float: none; "title=" 4.png "alt=" Wkiom1z43taxc7kmaaaj2dvmb1g688.png "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/78/3E/wKioL1Z43UiAskWtAAAuRjAKBRM565.png "style=" float: none; "title=" 5.png "alt=" Wkiol1z43uiaskwtaaaurjakbrm565.png "/>
4. Restart the NIC
650) this.width=650; "src=" Http://s5.51cto.com/wyfs02/M00/78/3E/wKioL1Z43aCxDFreAAALc7i8pMo331.png "style=" float: none; "title=" 6.png "alt=" Wkiol1z43acxdfreaaalc7i8pmo331.png "/>
5. Turn off ICMP redirection
650) this.width=650; "src=" Http://s5.51cto.com/wyfs02/M00/78/3E/wKioL1Z43aCivAegAAAKzKTWAno880.png "style=" float: none; "title=" 7.png "alt=" Wkiol1z43acivaegaaakzktwano880.png "/>
650) this.width=650; "src=" Http://s5.51cto.com/wyfs02/M00/78/3F/wKiom1Z43Y-j-hBvAAAR2-S9MwE450.png "style=" float: none; "title=" 8.png "alt=" Wkiom1z43y-j-hbvaaar2-s9mwe450.png "/>
6. Make the sysctl.conf file configuration effective
650) this.width=650; "src=" Http://s5.51cto.com/wyfs02/M01/78/3F/wKiom1Z43Y-AOEipAAAJXobrQEc762.png "style=" float: none; "title=" 9.png "alt=" Wkiom1z43y-aoeipaaajxobrqec762.png "/>
7. Set Ipvsadm boot automatically, empty the original strategy of IPVSADM
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M01/78/3E/wKioL1Z43aHAAH3dAAAp_W46MBs575.png "style=" float: none; "title=" 10.png "alt=" Wkiol1z43ahaah3daaap_w46mbs575.png "/>
8. Create a cluster, add a node
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/78/3F/wKiom1Z43gHib2MHAAAoN5QLkgY781.png "style=" float: none; "title=" 11.png "alt=" Wkiom1z43ghib2mhaaaon5qlkgy781.png "/>
9. Save the Ipvsadm policy
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/78/3E/wKioL1Z43hLwKOdcAAAX55nTSVU032.png "style=" float: none; "title=" 12.png "alt=" Wkiol1z43hlwkodcaaax55ntsvu032.png "/>
10. The node server shuts down the ARP response
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/78/3F/wKiom1Z43gGgvmNoAAAMSEdlHes046.png "style=" float: none; "title=" 13.png "alt=" Wkiom1z43gggvmnoaaamsedlhes046.png "/>
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/78/3E/wKioL1Z43hOST_eoAAAaSq38qI8732.png "style=" float: none; "title=" 14.png "alt=" Wkiol1z43host_eoaaaasq38qi8732.png "/>
11. Effective at the beginning
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/78/3E/wKioL1Z43hPysp7mAAAKB6HALaE330.png "style=" float: none; "title=" 15.png "alt=" Wkiol1z43hpysp7maaakb6halae330.png "/>
12. Node Server configuration VIP Address
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M01/78/3E/wKioL1Z43ouC5DfQAAAb5CYjC38705.png "style=" float: none; "title=" 16.png "alt=" Wkiol1z43ouc5dfqaaab5cyjc38705.png "/>
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M01/78/3F/wKiom1Z43nqxhW2sAAAqIjcr6kc934.png "style=" float: none; "title=" 17.png "alt=" Wkiom1z43nqxhw2saaaqijcr6kc934.png "/>
13. Add a local route entry
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M00/78/3E/wKioL1Z43ovQzQL8AAA9XuOe-7g818.png "style=" float: none; "title=" 18.png "alt=" Wkiol1z43ovqzql8aaa9xuoe-7g818.png "/>
14. When the client view the Web page,
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M02/78/3E/wKioL1Z43ovxskEvAAA34ozqOYE210.png "style=" float: none; "title=" 19.png "alt=" Wkiol1z43ovxskevaaa34ozqoye210.png "/>
650) this.width=650; "src=" Http://s2.51cto.com/wyfs02/M02/78/3F/wKiom1Z43nrDJ4bXAAAMAEjBkDI553.png "style=" float: none; "title=" 20.png "alt=" Wkiom1z43nrdj4bxaaamaejbkdi553.png "/>
Configuration Complete!
High-availability Cluster LVS Dr Mode Setup