LVS(NAT和DR)模式详细配置

环境准备

分别准备两台web服务器,两台服务器配置相同

[root@web1 ~]# yum install httpd* -y
[root@web1 ~]# iptables -F
[root@web1 ~]# /etc/init.d/iptables save
iptables: Saving firewall rules to /etc/sysconfig/iptables:[  OK  ]
[root@web1 ~]# /etc/init.d/iptables stop
iptables: Setting chains to policy ACCEPT: filter          [  OK  ]
iptables: Flushing firewall rules:                         [  OK  ]
iptables: Unloading modules:                               [  OK  ]
[root@web1 ~]# chkconfig iptables off
[root@web1 ~]# sed -i "s/SELINUX=enforcing/SELINUX disabled/g" /etc/selinux/config
[root@web1 ~]# setenforce 0
[root@web1 ~]# /etc/init.d/httpd start
[root@web1 ~]# ps -ef | grep httpd
root       1482      1  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1484   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1485   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1486   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1487   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1488   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1489   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1490   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
apache     1491   1482  0 18:24 ?        00:00:00 /usr/sbin/httpd
root       1494   1331  0 18:24 pts/0    00:00:00 grep httpd
[root@web1 ~]# netstat --lntup | grep 80
[root@web1 ~]# netstat -lntup | grep 80
tcp        0      0 :::80                       :::*                        LISTEN      1482/httpd
[root@web1 ~]# echo "webserver1" > /var/www/html/index.html

通过浏览器访问web服务器

LVS(NAT和DR)模式详细配置_第1张图片
web1

1、LVS-NAT模式

实验拓扑图:


LVS(NAT和DR)模式详细配置_第2张图片
LVS-NAT

安装ipvsadm:

[root@LVS ~]# yum install ipvsadm* -y
[root@LVS ~]# lsmod | grep lv_
[root@LVS ~]# lsmod | grep ip_vs
ip_vs_rr                1420  0 
ip_vs                 126897  2 ip_vs_rr
libcrc32c               1246  1 ip_vs
ipv6                  336282  270 ip_vs,ip6t_REJECT,nf_conntrack_ipv6,nf_defrag_ipv6

配置脚本如下:

#!/bin/bash

VIP=192.168.10.10 #外网用户直接访问网站的IP地址
RIP1=192.168.84.104 #后端web1服务器的IP地址
RIP2=192.168.84.105 #后端web2服务器的IP地址

case "$1" in
start)
    echo "Start LVS as the mode NAT"
    echo "1" > /proc/sys/net/ipv4/ip_forward #开启LVS服务器的IP路由转发功能
    /sbin/ifconfig eth0:0 $VIP netmask 255.255.255.0 up #设定VIP地址
    /sbin/ipvsadm -A -t $VIP:80 -s rr
    /sbin/ipvsadm -a -t $VIP:80 -r $RIP1 -m
    /sbin/ipvsadm -a -t $VIP:80 -r $RIP2 -m
    /sbin/ipvsadm 
    ;;
stop)
    echo "Stop LVS"
    echo "0" > /proc/sys/net/ipv4/ip_forward
    /sbin/ifconfig eth0:0 down
    ;;
*)  
    echo "Usage:$0 {start|stop}"
    exit 1
esac

运行脚本后结果如下:

[root@LVS ~]# sh lvs_nat.sh start
Start LVS as the mode NAT
IP Virtual Server version 1.2.1 (size=4096)
Prot LocalAddress:Port Scheduler Flags
  -> RemoteAddress:Port           Forward Weight ActiveConn InActConn
TCP  192.168.10.10:http rr
  -> 192.168.84.104:http          Masq    1      0          0         
  -> 192.168.84.105:http          Masq    1      0          0 

web服务器需要删除默认的路由网关,重新设置路由网关为LVS主机IP地址

[root@web1 ~]# route del default
[root@web1 ~]# route add default gateway 192.168.84.103
[root@web1 ~]# route
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
192.168.84.0    *               255.255.255.0   U     0      0        0 eth0
link-local      *               255.255.0.0     U     1002   0        0 eth0
default         192.168.84.103  0.0.0.0         UG    0      0        0 eth0

通过curl命令查看是否成功

[root@LVS ~]# curl 192.168.10.10
webserver2
[root@LVS ~]# curl 192.168.10.10
webserver1
[root@LVS ~]# curl 192.168.10.10
webserver2
[root@LVS ~]# curl 192.168.10.10
webserver1
[root@LVS ~]# curl 192.168.10.10
webserver2
[root@LVS ~]# curl 192.168.10.10
webserver1

2、LVS-DR模式

实验拓扑图:

LVS(NAT和DR)模式详细配置_第3张图片
LVS-DR

LVS-DR web服务器脚本

#!/bin/bash 
VIP=192.168.84.200 
/etc/rc.d/init.d/functions 
case "$1" in 
start) 
           echo "start LVS of RealServer DR" 
           /sbin/ifconfig lo:0 $VIP broadcast $VIP netmask 255.255.255.255 up 
           /sbin/route add -host $VIP dev lo:0  
           echo "1" >/proc/sys/net/ipv4/conf/lo/arp_ignore 
           echo "2" >/proc/sys/net/ipv4/conf/lo/arp_announce 
           echo "1" >/proc/sys/net/ipv4/conf/all/arp_ignore 
           echo "2" >/proc/sys/net/ipv4/conf/all/arp_announce  
       ;; 
stop) 
           /sbin/ifconfig lo:0 down 
           echo "close LVS of RealServer DR" 
           echo "0" >/proc/sys/net/ipv4/conf/lo/arp_ignore 
           echo "0" >/proc/sys/net/ipv4/conf/lo/arp_announce 
           echo "0" >/proc/sys/net/ipv4/conf/all/arp_ignore 
           echo "0" >/proc/sys/net/ipv4/conf/all/arp_announce 
           ;; 
  
*) 
          echo "Usage: $0 {start|stop}" 
          exit 1 
esac  
exit 0 

Lvs-DR 启动脚本

#!/bin/bash 
VIP=192.168.84.200 
RIP1=192.168.84.104 
RIP2=192.168.84.105
/etc/rc.d/init.d/functions 
case "$1" in 
start) 
           echo "start LVS of DirectorServer DR" 
           /sbin/ifconfig eth0:0 $VIP broadcast $VIP netmask 255.255.255.255 up 
           /sbin/route add -host $VIP dev eth0:0 
           echo "1" >/proc/sys/net/ipv4/ip_forward 
           /sbin/ipvsadm -C 
           /sbin/ipvsadm -A -t $VIP:80 -s rr  
           /sbin/ipvsadm -a -t $VIP:80 -r $RIP1:80 -g 
           /sbin/ipvsadm -a -t $VIP:80 -r $RIP2:80 -g 
           /sbin/ipvsadm 
       ;; 
stop) 
           echo "stop LVS of DirectorServer DR" 
           echo "0" >/proc/sys/net/ipv4/ip_forward 
           /sbin/ipvsadm -C 
           /sbin/ifconfig eth0:0 down 
           ;; 
*) 
          echo "Usage: $0 {start|stop}" 
          exit 1 
esac 
exit 0 

你可能感兴趣的:(LVS(NAT和DR)模式详细配置)