Re: [389-users] Accessing TCP options data in 389ds Hello,

2013-07-12 Thread Michael Lang
On 07/13/2013 12:07 AM, Grzegorz Dwornicki wrote: Ok thanks for clarification. I thought you might do this in simpler way. We are doing it in the following way (doesn't matter which load balancer you pick as long as it can preserve the real IP in which ever matter, like in IPVS it's called

Re: [389-users] Accessing TCP options data in 389ds Hello,

2013-07-12 Thread Grzegorz Dwornicki
Ok thanks for clarification. I thought you might do this in simpler way. 12 lip 2013 23:57, "Justin Kinney" napisał(a): > > > > On Fri, Jul 12, 2013 at 2:50 PM, Grzegorz Dwornicki wrote: >> >> That is true but load balancer iptables see incoming requests as they >> are. I'm not sure that this is

Re: [389-users] Accessing TCP options data in 389ds Hello,

2013-07-12 Thread Justin Kinney
On Fri, Jul 12, 2013 at 2:50 PM, Grzegorz Dwornicki wrote: > > That is true but load balancer iptables see incoming requests as they are. > I'm not sure that this is what you need. What information you wish to > receive? Besides the real client IP? > At the moment, the search node behind the load b

Re: [389-users] Accessing TCP options data in 389ds Hello,

2013-07-12 Thread Justin Kinney
On Fri, Jul 12, 2013 at 2:32 PM, Grzegorz Dwornicki wrote: > Are you doing this on loadbalancer? You can use iptables with log target > but if this is not sufficient, then some kind of sniffer like tcpdump might > be helpful > The loadbalancer will add the client ip address to the TCP options fie

Re: [389-users] Accessing TCP options data in 389ds Hello,

2013-07-12 Thread Justin Kinney
On Fri, Jul 12, 2013 at 2:28 PM, Rich Megginson wrote: > On 07/12/2013 03:25 PM, Justin Kinney wrote: > > Hello, > > I'm investigating the possibility of logging client IP address where > 389ds is deployed behind a load balancer. Today, we lose the true client IP > address as the source IP is

Re: [389-users] Accessing TCP options data in 389ds Hello,

2013-07-12 Thread Grzegorz Dwornicki
Are you doing this on loadbalancer? You can use iptables with log target but if this is not sufficient, then some kind of sniffer like tcpdump might be helpful 12 lip 2013 23:27, "Rich Megginson" napisał(a): > On 07/12/2013 03:25 PM, Justin Kinney wrote: > > Hello, > > I'm investigating the po