|
|||||||||||
|
Re: [Users] Load balance in VPN
From: John S. Denker <jsd(at)monmouth.com>
Date: Tue Feb 18 2003 - 21:42:56 EST On Tue, 18 Feb 2003, Silvio Luis Leite wrote: >>I have a situation that I want to implement two Linux Box with a FreesWan to
> The requirements is If source VPN packet is from X, Y, Z then use > lxFS1; or if source packet is > from Q, W, E, R then use lxFS2. Ken Bantoft wrote: > You will probably need iproute2 rules to achieve this - policy > routing based on both source and destination. That would do it.
Standard old NAT can't possibly do it.
This explains the observation that IKE msgs worked fine but ESP didn't get through. There is one huge question that needs to be answered: why bother with any of this? For pocket-change you can buy a CPU that is more than powerful enough to keep up with any ADSL line. So why use two? There cannot be any increase in throughput. There cannot be any increase in reliability. In fact the proposed design just decreases reliability. Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/users Received on Wed Feb 19 08:34:36 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:00:21 EDT |
||||||||||
|
|||||||||||