• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Inbound Loadbalancing - sticky connections- does not Round Robin

Scheduled Pinned Locked Moved HA/CARP/VIPs
12 Posts 5 Posters 7.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    gentis
    last edited by Dec 5, 2007, 1:07 AM Dec 4, 2007, 7:02 AM

    I'm attempting to host a VIP for inbound load-balancing on a pair of pfSense boxes Master and backup, with 2 web servers on the LAN side.
                                                                                                ->LAN  (Web Server1)
    HTTP Request -> Virtual IP (x.yy.zzz.333) CARP Load Balance Pool -> 
                                                                                                ->LAN (Web Server2)
    I have the load balancing pool setup - and the virtual server set up.  I'm passing tcp port "80" through WAN interface on the firewall (ALL HTTP traffic).

    Before enabling "sticky connections" LB worked great, distributing the load 50/50. But without the sticky connection we were having a hard time maintaining sessions to the same Web Server. After enabling "sticky connections" sessions from a source hosts are being handled my one web server. But it seems that all connections from source hosts are going to that same Web Server with out load balancing. I show that the status of the 2 web servers is Online (green).

    Any thoughts?

    Thanks.
    G

    1 Reply Last reply Reply Quote 0
    • G
      gentis
      last edited by Dec 5, 2007, 8:06 PM

      Anyone had this problem with sticky connections?

      1 Reply Last reply Reply Quote 0
      • G
        gentis
        last edited by Dec 6, 2007, 5:19 PM

        I found this topic in the forum to be similar to what I'm experiencing but there was not much of a resolution there.
        http://forum.pfsense.org/index.php/topic,4003.0.html

        1 Reply Last reply Reply Quote 0
        • G
          GruensFroeschli
          last edited by Dec 6, 2007, 5:25 PM

          How do you test/notice/experience that all connections go only to a single server?

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • S
            sullrich
            last edited by Apr 2, 2008, 4:38 AM

            Have you checked the Sticky Address option by chance?

            1 Reply Last reply Reply Quote 0
            • T
              tomato
              last edited by May 1, 2008, 4:06 PM

              Is there any way to get persistent connections using sticky option? ie. We need a session to last about 60 minutes
              during a transaction based on IP. Is that even possible? We were unable to get this to work using sticky connections etc.

              Thanks,

              1 Reply Last reply Reply Quote 0
              • H
                hoba
                last edited by May 1, 2008, 8:31 PM

                It looks like the sticky connection has issues (see the poll in the multiwan board). There is no other option to do something similiar atm. Maybe you can provide some info about your setup and what exactly is happening in that poll thread. The more informations we get the better we can debug it as it doesn't seem to be an issue for everyone.

                1 Reply Last reply Reply Quote 0
                • T
                  tomato
                  last edited by May 2, 2008, 1:28 PM

                  It was several months ago that I tried it. We setup an https LB pool with sticky set in Advanced.
                  Then I created a special rule for the https: Advanced options: State timeout 3600 (1 hour).

                  What we are trying to do: We want a way to have the same clients connect to the same https
                  servers for a period of at least 1 hour. Session and user data is stored locally.
                  (Eventually we will re-write the software so that each server is able to hand the session data correctly.)

                  My understanding at that time is that the browser needed to keep open the connection to keep
                  a persistent server talking to the same client. Since we could not do that, I assumed that what I was doing was not possible so we gave up. I've been researching persistent sessions and did find that pf has a souce-hash option that might work ala http://leaf.dragonflybsd.org/cgi/web-man?command=pf.conf§ion=5

                  I thought about using some custom rules with the source-hash options, but decided it was too
                  risky given that we already have a complex multi-unit carp setup.

                  1 Reply Last reply Reply Quote 0
                  • H
                    hoba
                    last edited by May 2, 2008, 10:17 PM

                    The state timeout only affects idle states but when you connect to an https server you open a state, get the data and colse the state after the data was transferred again. It won't keep that state alive so the statetimeouts won't work here.

                    1 Reply Last reply Reply Quote 0
                    • T
                      tomato
                      last edited by May 5, 2008, 1:27 PM

                      Hoba,

                      Do you think posting a bounty for source-hashed  pools would be helpful?
                        What other options can you recommend?

                      1 Reply Last reply Reply Quote 0
                      • H
                        hoba
                        last edited by May 5, 2008, 7:34 PM

                        I can't say for sure but bounties will always help to raise interest and as this is a rather hot topic others might jump on that bounty to add more money as well. Give it a try and see what happens. Unfortunately I don't have another solution at hand right now.

                        1 Reply Last reply Reply Quote 0
                        • G
                          gentis
                          last edited by Jun 24, 2008, 6:42 PM

                          How do i configure Sticky Address? And what is the behavior with this option?
                          Thanks
                          G

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            [[user:consent.lead]]
                            [[user:consent.not_received]]