Egress of multiple machines through one IP

Simon Huggins huggie at earth.li
Tue Sep 14 13:13:06 CEST 2010


On Fri, Sep 10, 2010 at 04:36:29PM +0200, Marco d'Itri wrote:
> On Sep 10, Simon Huggins <huggie at earth.li> wrote:
> > Anyone any other good ideas?
> Two redundant load balancers with sticky sessions in front of the
> proxies, then the outgoing IP will not matter anymore.
> You can easily install LVS on two of the proxy nodes, its CPU usage is
> negligible (but you will need a recent kernel for IPv6 support).

The nature of our traffic means stickiness doesn't work so well for us.

We basically proxy for lots of large corporates.  They often have the
same IP from our point of view for lots of their users.  So we can't
easily balance that traffic on the way in based on IP.  It's possible we
could balance on something else but I'm sure some of our dear customers
would confound our plans.

I'm still pondering this one.

-- 
Simon  [ huggie at earth.li ] *\     "There's no emoticon for what I'm  \**
****** ]-+-+-+-+-+-+-+-+-[ **\      feeling!" -- Comic Book Guy, The  \*
****** [  Htag.pl 0.0.24 ] ***\                             Simpsons.  \
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL: <https://lists.cluenet.de/pipermail/ipv6-ops/attachments/20100914/65742f2e/attachment.sig>


More information about the ipv6-ops mailing list