第 3 章 设​​​​​​​置​​​​​​​ LVS


LVS 群​​​​​​​集​​​​​​​包​​​​​​​括​​​​​​​两​​​​​​​个​​​​​​​基​​​​​​​本​​​​​​​群​​​​​​​组​​​​​​​:LVS 路​​​​​​​由​​​​​​​器​​​​​​​和​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​。​​​​​​​要​​​​​​​防​​​​​​​止​​​​​​​单​​​​​​​点​​​​​​​失​​​​​​​败​​​​​​​,每​​​​​​​个​​​​​​​群​​​​​​​组​​​​​​​应​​​​​​​该​​​​​​​包​​​​​​​含​​​​​​​至​​​​​​​少​​​​​​​两​​​​​​​个​​​​​​​成​​​​​​​员​​​​​​​系​​​​​​​统​​​​​​​。​​​​​​​
LVS 路​​​​​​​由​​​​​​​器​​​​​​​群​​​​​​​组​​​​​​​应​​​​​​​该​​​​​​​包​​​​​​​括​​​​​​​两​​​​​​​个​​​​​​​相​​​​​​​同​​​​​​​或​​​​​​​者​​​​​​​非​​​​​​​常​​​​​​​类​​​​​​​似​​​​​​​的​​​​​​​运​​​​​​​行​​​​​​​Red Hat Enterprise Linux 的​​​​​​​系​​​​​​​统​​​​​​​。​​​​​​​其​​​​​​​中​​​​​​​一​​​​​​​个​​​​​​​作​​​​​​​为​​​​​​​活​​​​​​​跃​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​使​​​​​​​用​​​​​​​,同​​​​​​​时​​​​​​​另​​​​​​​一​​​​​​​个​​​​​​​处​​​​​​​于​​​​​​​热​​​​​​​等​​​​​​​待​​​​​​​模​​​​​​​式​​​​​​​,因​​​​​​​此​​​​​​​它​​​​​​​们​​​​​​​需​​​​​​​要​​​​​​​有​​​​​​​尽​​​​​​​可​​​​​​​能​​​​​​​相​​​​​​​似​​​​​​​的​​​​​​​容​​​​​​​量​​​​​​​。​​​​​​​
在​​​​​​​为​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​组​​​​​​​群​​​​​​​选​​​​​​​择​​​​​​​和​​​​​​​配​​​​​​​置​​​​​​​硬​​​​​​​件​​​​​​​时​​​​​​​,您​​​​​​​必​​​​​​​须​​​​​​​决​​​​​​​定​​​​​​​使​​​​​​​用​​​​​​​三​​​​​​​种​​​​​​​ LVS 布​​​​​​​局​​​​​​​中​​​​​​​的​​​​​​​哪​​​​​​​一​​​​​​​种​​​​​​​。​​​​​​​

3.1. NAT LVS 网​​​​​​​络​​​​​​​

NAT 布​​​​​​​局​​​​​​​允​​​​​​​许​​​​​​​大​​​​​​​限​​​​​​​度​​​​​​​利​​​​​​​用​​​​​​​现​​​​​​​有​​​​​​​硬​​​​​​​件​​​​​​​,但​​​​​​​因​​​​​​​为​​​​​​​所​​​​​​​有​​​​​​​进​​​​​​​出​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​池​​​​​​​的​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​都​​​​​​​经​​​​​​​过​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​,所​​​​​​​以​​​​​​​会​​​​​​​限​​​​​​​制​​​​​​​其​​​​​​​处​​​​​​​理​​​​​​​大​​​​​​​负​​​​​​​载​​​​​​​的​​​​​​​能​​​​​​​力​​​​​​​。​​​​​​​
网​​​​​​​络​​​​​​​布​​​​​​​局​​​​​​​
使​​​​​​​用​​​​​​​ NAT 路​​​​​​​由​​​​​​​的​​​​​​​ LVS 布​​​​​​​局​​​​​​​是​​​​​​​根​​​​​​​据​​​​​​​网​​​​​​​络​​​​​​​方​​​​​​​案​​​​​​​透​​​​​​​视​​​​​​​进​​​​​​​行​​​​​​​配​​​​​​​置​​​​​​​的​​​​​​​最​​​​​​​简​​​​​​​单​​​​​​​的​​​​​​​方​​​​​​​法​​​​​​​,因​​​​​​​为​​​​​​​只​​​​​​​需​​​​​​​要​​​​​​​一​​​​​​​个​​​​​​​切​​​​​​​入​​​​​​​点​​​​​​​访​​​​​​​问​​​​​​​公​​​​​​​共​​​​​​​网​​​​​​​络​​​​​​​。​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​会​​​​​​​将​​​​​​​所​​​​​​​有​​​​​​​请​​​​​​​求​​​​​​​返​​​​​​​回​​​​​​​到​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​,这​​​​​​​样​​​​​​​就​​​​​​​可​​​​​​​以​​​​​​​让​​​​​​​它​​​​​​​们​​​​​​​在​​​​​​​其​​​​​​​专​​​​​​​用​​​​​​​网​​​​​​​络​​​​​​​中​​​​​​​了​​​​​​​。​​​​​​​
硬​​​​​​​件​​​​​​​
从​​​​​​​硬​​​​​​​件​​​​​​​考​​​​​​​虑​​​​​​​,NAT 布​​​​​​​局​​​​​​​是​​​​​​​最​​​​​​​灵​​​​​​​活​​​​​​​的​​​​​​​布​​​​​​​局​​​​​​​,因​​​​​​​为​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​不​​​​​​​一​​​​​​​定​​​​​​​是​​​​​​​ Linux 机​​​​​​​器​​​​​​​才​​​​​​​能​​​​​​​正​​​​​​​常​​​​​​​工​​​​​​​作​​​​​​​。​​​​​​​在​​​​​​​ NAT 布​​​​​​​局​​​​​​​中​​​​​​​,每​​​​​​​个​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​只​​​​​​​需​​​​​​​要​​​​​​​一​​​​​​​个​​​​​​​ NIC,因​​​​​​​为​​​​​​​它​​​​​​​只​​​​​​​响​​​​​​​应​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​。​​​​​​​另​​​​​​​一​​​​​​​方​​​​​​​面​​​​​​​,LVS 路​​​​​​​由​​​​​​​器​​​​​​​需​​​​​​​要​​​​​​​两​​​​​​​个​​​​​​​ NIC 来​​​​​​​在​​​​​​​两​​​​​​​个​​​​​​​网​​​​​​​络​​​​​​​间​​​​​​​路​​​​​​​由​​​​​​​流​​​​​​​量​​​​​​​。​​​​​​​因​​​​​​​为​​​​​​​此​​​​​​​布​​​​​​​局​​​​​​​在​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​中​​​​​​​产​​​​​​​生​​​​​​​了​​​​​​​网​​​​​​​络​​​​​​​瓶​​​​​​​颈​​​​​​​,所​​​​​​​以​​​​​​​可​​​​​​​以​​​​​​​在​​​​​​​每​​​​​​​个​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​中​​​​​​​部​​​​​​​署​​​​​​​千​​​​​​​兆​​​​​​​以​​​​​​​太​​​​​​​网​​​​​​​ NIC(gigabit Ethernet NIC)来​​​​​​​提​​​​​​​高​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​可​​​​​​​处​​​​​​​理​​​​​​​的​​​​​​​带​​​​​​​宽​​​​​​​。​​​​​​​如​​​​​​​果​​​​​​​在​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​中​​​​​​​使​​​​​​​用​​​​​​​了​​​​​​​千​​​​​​​兆​​​​​​​以​​​​​​​太​​​​​​​网​​​​​​​ NIC,每​​​​​​​个​​​​​​​连​​​​​​​接​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​和​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​的​​​​​​​开​​​​​​​关​​​​​​​必​​​​​​​须​​​​​​​至​​​​​​​少​​​​​​​有​​​​​​​两​​​​​​​个​​​​​​​千​​​​​​​兆​​​​​​​以​​​​​​​太​​​​​​​网​​​​​​​端​​​​​​​口​​​​​​​来​​​​​​​有​​​​​​​效​​​​​​​处​​​​​​​理​​​​​​​负​​​​​​​载​​​​​​​。​​​​​​​
软​​​​​​​件​​​​​​​
因​​​​​​​为​​​​​​​ NAT 布​​​​​​​局​​​​​​​需​​​​​​​要​​​​​​​使​​​​​​​用​​​​​​​ iptables 进​​​​​​​行​​​​​​​某​​​​​​​些​​​​​​​配​​​​​​​置​​​​​​​,所​​​​​​​以​​​​​​​在​​​​​​​ Piranha Configuration Tool之​​​​​​​外​​​​​​​还​​​​​​​需​​​​​​​要​​​​​​​配​​​​​​​置​​​​​​​相​​​​​​​当​​​​​​​数​​​​​​​量​​​​​​​的​​​​​​​软​​​​​​​件​​​​​​​。​​​​​​​特​​​​​​​别​​​​​​​是​​​​​​​在​​​​​​​使​​​​​​​用​​​​​​​FTP 服​​​​​​​务​​​​​​​和​​​​​​​防​​​​​​​火​​​​​​​墙​​​​​​​标​​​​​​​记​​​​​​​时​​​​​​​需​​​​​​​要​​​​​​​额​​​​​​​外​​​​​​​手​​​​​​​动​​​​​​​配​​​​​​​置​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​以​​​​​​​便​​​​​​​正​​​​​​​确​​​​​​​路​​​​​​​由​​​​​​​请​​​​​​​求​​​​​​​。​​​​​​​

3.1.1. 为​​​​​​​带​​​​​​​ NAT 的​​​​​​​ LVS 配​​​​​​​置​​​​​​​网​​​​​​​络​​​​​​​接​​​​​​​口​​​​​​​

To set up LVS with NAT, you must first configure the network interfaces for the public network and the private network on the LVS routers. In this example, the LVS routers' public interfaces (eth0) will be on the 192.168.26/24 network (I know, I know, this is not a routable IP, but let us pretend there is a firewall in front of the LVS router for good measure) and the private interfaces which link to the real servers (eth1) will be on the 10.11.12/24 network.
So on the active or primary LVS router node, the public interface's network script, /etc/sysconfig/network-scripts/ifcfg-eth0, could look something like this:
DEVICE=eth0
BOOTPROTO=static
ONBOOT=yes
IPADDR=192.168.26.9
NETMASK=255.255.255.0
GATEWAY=192.168.26.254
专​​​​​​​用​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​ NAT 接​​​​​​​口​​​​​​​的​​​​​​​ /etc/sysconfig/network-scripts/ifcfg-eth1 应​​​​​​​类​​​​​​​似​​​​​​​如​​​​​​​下​​​​​​​:
DEVICE=eth1
BOOTPROTO=static
ONBOOT=yes
IPADDR=10.11.12.9
NETMASK=255.255.255.0
In this example, the VIP for the LVS router's public interface will be 192.168.26.10 and the VIP for the NAT or private interface will be 10.11.12.10. So, it is essential that the real servers route requests back to the VIP for the NAT interface.

重要

The sample Ethernet interface configuration settings in this section are for the real IP addresses of an LVS router and not the floating IP addresses. To configure the public and private floating IP addresses the administrator should use the Piranha Configuration Tool, as shown in 第 4.4 节 “GLOBAL SETTINGS and 第 4.6.1 节 “「​​​​​​​虚​​​​​​​拟​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​」​​​​​​​子​​​​​​​界​​​​​​​面​​​​​​​”.
After configuring the primary LVS router node's network interfaces, configure the backup LVS router's real network interfaces — taking care that none of the IP address conflict with any other IP addresses on the network.

重要

请​​​​​​​确​​​​​​​定​​​​​​​每​​​​​​​个​​​​​​​位​​​​​​​于​​​​​​​备​​​​​​​用​​​​​​​节​​​​​​​点​​​​​​​接​​​​​​​口​​​​​​​的​​​​​​​服​​​​​​​务​​​​​​​提​​​​​​​供​​​​​​​与​​​​​​​主​​​​​​​节​​​​​​​点​​​​​​​相​​​​​​​同​​​​​​​的​​​​​​​接​​​​​​​口​​​​​​​。​​​​​​​例​​​​​​​如​​​​​​​,如​​​​​​​果​​​​​​​在​​​​​​​主​​​​​​​节​​​​​​​点​​​​​​​中​​​​​​​使​​​​​​​用​​​​​​​ eth0 连​​​​​​​接​​​​​​​到​​​​​​​公​​​​​​​共​​​​​​​网​​​​​​​络​​​​​​​,那​​​​​​​么​​​​​​​也​​​​​​​要​​​​​​​使​​​​​​​用​​​​​​​它​​​​​​​在​​​​​​​备​​​​​​​用​​​​​​​节​​​​​​​点​​​​​​​连​​​​​​​接​​​​​​​公​​​​​​​共​​​​​​​网​​​​​​​络​​​​​​​。​​​​​​​

3.1.2. 在​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​中​​​​​​​路​​​​​​​由​​​​​​​

在​​​​​​​配​​​​​​​置​​​​​​​ NAT 布​​​​​​​局​​​​​​​的​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​网​​​​​​​络​​​​​​​接​​​​​​​口​​​​​​​时​​​​​​​,最​​​​​​​重​​​​​​​要​​​​​​​的​​​​​​​是​​​​​​​要​​​​​​​记​​​​​​​住​​​​​​​为​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​的​​​​​​​ NAT 浮​​​​​​​动​​​​​​​ IP 地​​​​​​​址​​​​​​​设​​​​​​​定​​​​​​​网​​​​​​​关​​​​​​​。​​​​​​​在​​​​​​​本​​​​​​​示​​​​​​​例​​​​​​​中​​​​​​​,该​​​​​​​地​​​​​​​址​​​​​​​应​​​​​​​该​​​​​​​是​​​​​​​ 10.11.12.10。​​​​​​​

注意

Once the network interfaces are up on the real servers, the machines will be unable to ping or connect in other ways to the public network. This is normal. You will, however, be able to ping the real IP for the LVS router's private interface, in this case 10.11.12.8.
So the real server's /etc/sysconfig/network-scripts/ifcfg-eth0 file could look similar to this:
DEVICE=eth0
ONBOOT=yes
BOOTPROTO=static
IPADDR=10.11.12.1
NETMASK=255.255.255.0
GATEWAY=10.11.12.10

警告

如​​​​​​​果​​​​​​​真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​有​​​​​​​超​​​​​​​过​​​​​​​一​​​​​​​个​​​​​​​网​​​​​​​络​​​​​​​接​​​​​​​口​​​​​​​配​​​​​​​置​​​​​​​了​​​​​​​ GATEWAY= 行​​​​​​​,第​​​​​​​一​​​​​​​个​​​​​​​出​​​​​​​现​​​​​​​的​​​​​​​将​​​​​​​是​​​​​​​网​​​​​​​关​​​​​​​。​​​​​​​因​​​​​​​此​​​​​​​,如​​​​​​​果​​​​​​​同​​​​​​​时​​​​​​​配​​​​​​​置​​​​​​​了​​​​​​​ eth0 和​​​​​​​ eth1,而​​​​​​​且​​​​​​​ eth1 用​​​​​​​于​​​​​​​ LVS,真​​​​​​​实​​​​​​​服​​​​​​​务​​​​​​​器​​​​​​​可​​​​​​​能​​​​​​​无​​​​​​​法​​​​​​​正​​​​​​​确​​​​​​​路​​​​​​​由​​​​​​​请​​​​​​​求​​​​​​​。​​​​​​​
最​​​​​​​好​​​​​​​是​​​​​​​在​​​​​​​他​​​​​​​们​​​​​​​位​​​​​​​于​​​​​​​ /etc/sysconfig/network-scripts/ 目​​​​​​​录​​​​​​​的​​​​​​​网​​​​​​​络​​​​​​​脚​​​​​​​本​​​​​​​ ONBOOT=no 中​​​​​​​设​​​​​​​定​​​​​​​关​​​​​​​闭​​​​​​​无​​​​​​​关​​​​​​​的​​​​​​​网​​​​​​​络​​​​​​​接​​​​​​​口​​​​​​​,或​​​​​​​者​​​​​​​确​​​​​​​定​​​​​​​在​​​​​​​第​​​​​​​一​​​​​​​个​​​​​​​要​​​​​​​出​​​​​​​现​​​​​​​的​​​​​​​接​​​​​​​口​​​​​​​中​​​​​​​正​​​​​​​确​​​​​​​设​​​​​​​置​​​​​​​了​​​​​​​网​​​​​​​关​​​​​​​。​​​​​​​

3.1.3. 启​​​​​​​动​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​中​​​​​​​的​​​​​​​ NAT 路​​​​​​​由​​​​​​​

In a simple NAT LVS configuration where each clustered service uses only one port, like HTTP on port 80, the administrator needs only to enable packet forwarding on the LVS routers for the requests to be properly routed between the outside world and the real servers. See 第 2.5 节 “启​​​​​​​动​​​​​​​数​​​​​​​据​​​​​​​包​​​​​​​转​​​​​​​发​​​​​​​” for instructions on turning on packet forwarding. However, more configuration is necessary when the clustered services require more than one port to go to the same real server during a user session. For information on creating multi-port services using firewall marks, see 第 3.4 节 “多​​​​​​​端​​​​​​​口​​​​​​​服​​​​​​​务​​​​​​​和​​​​​​​ LVS ”.
Once forwarding is enabled on the LVS routers and the real servers are set up and have the clustered services running, use the Piranha Configuration Tool to configure LVS as shown in 第 4 章 用​​​​​​​ Piranha Configuration Tool配​​​​​​​置​​​​​​​ LVS 路​​​​​​​由​​​​​​​器​​​​​​​.

警告

When finished, start the pulse service as shown in 第 4.8 节 “启​​​​​​​动​​​​​​​ LVS”. Once pulse is up and running, the active LVS router will begin routing requests to the pool of real servers.
Red Hat logoGithubRedditYoutubeTwitter

学习

尝试、购买和销售

社区

关于红帽文档

通过我们的产品和服务,以及可以信赖的内容,帮助红帽用户创新并实现他们的目标。

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

© 2024 Red Hat, Inc.