1、理论部分
1.1、LVS的架构
调度层(Director):
集群层(Real Server)
共享层
1.2、LVS的三种工作模式
1)DR模式
- MAC层实现
- Director将请求的数据包目标MAC改为Real Server的MAC地址
- 数据直接返回客户端
2)NAT模式
- IP层实现
- Director将请求的目标IP改为Real Server的IP
- 数据返回在Director将源IP还原
3)TUN模式
- 类似于VPN实现
- Director建立加密IP隧道转发到Real Server
- 数据直接返回客户端
1.3、LVS的IP分类
1)VIP(Virtual IP)
- VIP每台机都需要配置
- IP用于内网通讯并对外提供服务
2)DIP(Driector IP)
- DIP设置于Driector服务器
- 分内外网IP,内网IP用于内部通讯,外网IP用于NAT模式的外网
3)RIP(Real IP)
- RIP设置于Real服务器
- 只有内网IP,IP只用于内网通讯
1.4、LVS的调度算法:
1)轮叫调度(Round Robin,简称RR)
2)加权轮叫(Weighted Round Robin,简称WRR)
3)最少链接(Least Connection,简称LC)
4)加权最少链接(Weighted Least Conncetions,简称WLC)
2、实验部分
2.1、实验前提
1)主机信息
Dr:
director ipaddress=10.168.0.90
vip ipaddress=10.168.0.91
hostname=dr
Rs1:
real ipaddress=10.168.0.94
vip-lo ipaddress=10.168.0.91
hostname=rs1
Rs2:
real ipaddress=10.168.0.95
vip-lo ipaddress=10.168.0.91
hostname=rs2
2)yum源
In Real Server
yum install -y httpd
In Director
yum install -y ipvsad
2.1、NAT模式配置
vim增加/usr/local/sbin/lvs_nat.sh
#! /bin/bash # director 服务器上开启路由转发功能: echo 1 > /proc/sys/net/ipv4/ip_forward # 关闭icmp的重定向 echo 0 > /proc/sys/net/ipv4/conf/all/send_redirects echo 0 > /proc/sys/net/ipv4/conf/default/send_redirects echo 0 > /proc/sys/net/ipv4/conf/eth0/send_redirects echo 0 > /proc/sys/net/ipv4/conf/eth1/send_redirects # director 设置nat防火墙 iptables -t nat -F iptables -t nat -X iptables -t nat -A POSTROUTING -s 10.168.0.0/24 -j MASQUERADE # director设置ipvsadm IPVSADM=‘/sbin/ipvsadm‘ $IPVSADM -C $IPVSADM -A -t 192.168.0.11:80 -s lc -p 300 $IPVSADM -a -t 192.168.0.11:80 -r 10.168.0.94:80 -m -w 1 $IPVSADM -a -t 192.168.0.11:80 -r 10.168.0.95:80 -m -w 1
运行脚本:
sh /usr/local/sbin/lvs_nat.sh
2.2、DR模式配置
In Director
vim增加/usr/local/sbin/lvs_dr.sh
#! /bin/bash echo 1 > /proc/sys/net/ipv4/ip_forward ipv=/sbin/ipvsadm vip=10.168.0.91 rs1=10.168.0.94 rs2=10.168.0.95 ifconfig eth0:0 $vip broadcast $vip netmask 255.255.255.255 up route add -host $vip dev eth0:0 $ipv -C $ipv -A -t $vip:80 -s rr $ipv -a -t $vip:80 -r $rs1:80 -g -w 1 $ipv -a -t $vip:80 -r $rs2:80 -g -w 1
In Real Server
vim增加/usr/local/sbin/lvs_dr_rs.sh
#! /bin/bash vip=10.168.0.91 ifconfig lo:0 $vip broadcast $vip netmask 255.255.255.255 up route add -host $vip lo:0 echo "1" >/proc/sys/net/ipv4/conf/lo/arp_ignore echo "2" >/proc/sys/net/ipv4/conf/lo/arp_announce echo "1" >/proc/sys/net/ipv4/conf/all/arp_ignore echo "2" >/proc/sys/net/ipv4/conf/all/arp_announce
运行脚本:
In Director
/usr/local/sbin/lvs_dr.sh
In Real Server
sh /usr/local/sbin/lvs_dr_rs.sh
参考文献:
LVS-DR的工作原理
http://os.51cto.com/art/201105/264303.htm
LVS调度算法分类:
http://www.apelearn.com/bbs/thread-7407-1-1.html
arp_ignore&arp_announce参数(DR模式):
http://www.cnblogs.com/lgfeng/archive/2012/10/16/2726308.html