cloudstack-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Edison Su <Edison...@citrix.com>
Subject RE: Client source IP visibility
Date Mon, 16 Jul 2012 17:53:52 GMT


> -----Original Message-----
> From: Fabrice Brazier [mailto:fabrice.brazier@apalia.net]
> Sent: Monday, July 16, 2012 1:56 AM
> To: cloudstack-users@incubator.apache.org
> Cc: cloudstack
> Subject: Client source IP visibility
> 
> Hi Folks,
> 
> 
> 
> we need a way of configuring CloudStack load balancing with the
> integrated
> ha-proxy load balancer without hiding the client (source) IP.
> 
> We see TPPROXY feature as a way of doing this, see
> http://blog.loadbalancer.org/configure-haproxy-with-tproxy-kernel-for-
> full-transparent-proxy/
> .
> 
> 
> 
> Does this functionality is already implemented ? Will be in the future?
> 

It needs special kernel, not sure it works in debian squeeze kernel or not.

> 
> 
> A possible workaround would be to use the "X-Forwarded-For" header for
> filtering IP addresses.

"option forwardfor" is already in haproxy configuration file, by default.
Doesn't it work for you? If not, please fire a bug.

> 
> 
> 
> Thanks,
> 
> Fabrice
> 
> 
> 
> --
> Fabrice Brazier
> *Apalia*(tm)*
> *FR: +33-632-73-53-00
> *http://www.apalia.net
> fabrice.brazier@apalia.net*

Mime
View raw message