拓扑图:
环境 : 4台服务器都是 redhat5.4
软件 : keepalived-1.2.6、 ipvsadm-1.2.4、 nginx-1.5.2
配置:
node
tar -zxvf keepalived-1.2.6.tar.gz-C /usr/local/src/
cd /usr/local/src/keepalived-1.2.6/
cp /usr/local/etc/rc.d/init.d/keepalived/etc/init.d/
cp /usr/local/etc/sysconfig/keepalived/etc/sysconfig/
mkdir /etc/keepalived
cp /usr/local/sbin/keepalived /usr/sbin/
cp/usr/local/etc/keepalived/keepalived.conf /etc/keepalived/
vim /etc/keepalived/keepalived.conf
yum install ipvsadm
[root@node1 ~]# vim /etc/keepalived/keepalived.conf
! Configuration File for keepalived
global_defs {
notification_email {
# acassen@firewall.loc
# failover@firewall.loc
root@localhost }
notification_email_from root@localhost
smtp_server smtp.localhost
smtp_connect_timeout 30
router_id LVS_DEVEL
}
默认的配置文件中,使用第三方 smtp服务器,但这在现实中几乎没有意义(需要验证的原因),我们将其指定为 localhost,将通知信息的发送交给本地 sendmail服务处理。查阅说明文档得知 route_id配置是为了标识当前节点,当然两个节点的此项设置可相同,也可不相同。
vrrp_instance VI_1 {
state MASTER #指定 A节点为主节点 备用节点上设置为 BACKUP即可
interface eth0 #绑定虚拟 IP的网络接口
virtual_router_id 51 #VRRP组名,两个节点的设置必须一样,以指明各个节点属于同一 VRRP组
priority 100 #主节点的优先级( 1-254之间),备用节点必须比主节点优先级低
advert_int 1 #组播信息发送间隔,两个节点设置必须一样
authentication { #设置验证信息,两个节点必须一致
auth_typePASS
auth_pass 1111
}
virtual_ipaddress { #指定虚拟 IP, 两个节点设置必须一样
222.22.49.4
#192.168.200.18/24
}
默认的配置文件中,竟然没有子网掩码,从而导致使用了默认子网掩码 255.255.255.255,如果导致无法从其它机器访问虚拟 IP( keepalived虚拟 IP无法 ping通)。
}
virtual_server 222.22.49.4 80 {
delay_loop 3
lb_algo rr
lb_kind TUN #有三种模式 NAT 、 DR 、 TUN
protocol TCP
ha_suspend
real_server 211.10.10.2 80 {
weight 1
TCP_CHECK {
connect_port 80
connect_timeout 3
}
}
real_server 124.202.148.15 80 {
weight 1
TCP_CHECK {
connect_port 80
connect_timeout 3
}
}
}
测试及验证:拔掉节点 A的网线,就发现虚拟 IP已经绑定到节点 B上,再恢复 A节点的网线,虚拟 IP又绑定回节点 A之上。
为了实现更多的功能可以添加脚本
vrrp_script及 track_script实现:
在 keepalived的配置文件最前面加入以下代码,定义一个脚本:
vrrp_script check_local { #定义一个名称为 check_local的检查脚本
script "/usr/local/keepalived/bin/check_local.sh" #shell脚本的路径
interval 5 #运行间隔
}
再在 vrrp_instance配置中加入以下代码使用上面定义的脚本:
track_script {
check_local
}
我们在 /usr/local/keepalived/bin/check_local.sh中写我们的脚本
realserver
搭建 nginx环境参见 http://zhoulinjun.blog.运维网.com/3911076/1253921
[root@localhost network-scripts]# vim/etc/rc.local
#!/bin/sh
#
# This script will be executed *after* allthe other init scripts.
# You can put your own initialization stuffin here if you don't
# want to do the full Sys V style initstuff.
touch /var/lock/subsys/local
route add -host 222.22.49.4 dev tunl0
/usr/local/nginx/sbin/nginx
[root@localhost network-scripts]# vim/etc/sysconfig/network-scripts/ifcfg-tunl0
TYPE=Ethernet
HWaddr=00:00:00:00:00:00
DEVICE=tunl0
BOOTPROTO=none
NETMASK=255.255.255.255
IPADDR=222.22.49.4
在 windowsserver 2008 R2上做 lvs/DR模式时
windows服务器配置:
在 2008R2上添加了 loopback adapter,配置 VIP 222.22.49.4,掩码 255.255.255.255 网关指定 222.22.49.4。在 windows 在两台 windows上搭建好 IIS,建立站点,需要输入一下命令:
netsh interface ipv4 set interface"net" weakhostreceive=enabled
netsh interface ipv4 set interface"net" weakhostsend=enabled
netsh interface ipv4 set interface"loopback" weakhostreceive=enabled
netsh interface ipv4 set interface"loopback" weakhostsend=enabled
测试:
[root@node1 ~]# ip add
1: lo: mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: mtu 1500 qdisc pfifo_fast qlen 1000
link/ether 00:0c:29:ac:a9:e3 brd ff:ff:ff:ff:ff:ff
inet 222.22.49.2/24 brd 222.22.49.255 scope global eth0
inet 222.22.49.4/32 scope global eth0
inet6 fe80::20c:29ff:feac:a9e3/64 scope link
valid_lft forever preferred_lft forever
3: sit0: mtu 1480 qdisc noop
link/sit 0.0.0.0 brd 0.0.0.0
[root@node2 ~]# ip add
1: lo: mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: mtu 1500 qdisc pfifo_fast qlen 1000
link/ether 00:0c:29:06:bb:52 brd ff:ff:ff:ff:ff:ff
inet 222.22.49.3/24 brd 222.22.49.255 scope global eth0
inet6 fe80::20c:29ff:fe06:bb52/64 scope link
valid_lft forever preferred_lft forever
3: sit0: mtu 1480 qdisc noop
link/sit 0.0.0.0 brd 0.0.0.0
[root@node2 ~]#
[root@node1 ~]# ipvsadm -l
IP Virtual Server version 1.2.1(size=4096)
Prot LocalAddress:Port Scheduler Flags
-> RemoteAddress:Port Forward Weight ActiveConn InActConn
TCP 222.22.49.4:http rr
-> 124.202.148.15:http Tunnel 1 1 1
-> 211.10.10.2:http Tunnel 1 1 2
[root@node1 ~]#
[root@localhost ~]#/usr/local/nginx/sbin/nginx -s stop
[root@node1 ~]# ipvsadm -l
IP Virtual Server version 1.2.1(size=4096)
Prot LocalAddress:Port Scheduler Flags
-> RemoteAddress:Port Forward Weight ActiveConn InActConn
TCP 222.22.49.4:http rr
-> 124.202.148.15:http Tunnel 1 0 2
[root@node1 ~]#
[root@node1 ~]# service keepalived stop
[root@node1 ~]# ip add
1: lo: mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: mtu 1500 qdisc pfifo_fast qlen 1000
link/ether 00:0c:29:ac:a9:e3 brd ff:ff:ff:ff:ff:ff
inet 222.22.49.2/24 brd 222.22.49.255 scope global eth0
inet6 fe80::20c:29ff:feac:a9e3/64 scope link
valid_lft forever preferred_lft forever
3: sit0: mtu 1480 qdisc noop
link/sit 0.0.0.0 brd 0.0.0.0
[root@node1 ~]#
[root@node2 ~]# ip add
1: lo: mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: mtu 1500 qdisc pfifo_fast qlen 1000
link/ether 00:0c:29:06:bb:52 brd ff:ff:ff:ff:ff:ff
inet 222.22.49.3/24 brd 222.22.49.255 scope global eth0
inet 222.22.49.4/32 scope global eth0
inet6 fe80::20c:29ff:fe06:bb52/64 scope link
valid_lft forever preferred_lft forever
3: sit0: mtu 1480 qdisc noop
link/sit 0.0.0.0 brd 0.0.0.0
[root@node2 ~]#
[root@node2 ~]# ipvsadm -l
IP Virtual Server version 1.2.1(size=4096)
Prot LocalAddress:Port Scheduler Flags
-> RemoteAddress:Port Forward Weight ActiveConn InActConn
TCP 222.22.49.4:http rr
-> 124.202.148.15:http Tunnel 1 1 1
[root@node2 ~]#
运维网声明
1、欢迎大家加入本站运维交流群:群②:261659950 群⑤:202807635 群⑦870801961 群⑧679858003
2、本站所有主题由该帖子作者发表,该帖子作者与运维网 享有帖子相关版权
3、所有作品的著作权均归原作者享有,请您和我们一样尊重他人的著作权等合法权益。如果您对作品感到满意,请购买正版
4、禁止制作、复制、发布和传播具有反动、淫秽、色情、暴力、凶杀等内容的信息,一经发现立即删除。若您因此触犯法律,一切后果自负,我们对此不承担任何责任
5、所有资源均系网友上传或者通过网络收集,我们仅提供一个展示、介绍、观摩学习的平台,我们不对其内容的准确性、可靠性、正当性、安全性、合法性等负责,亦不承担任何法律责任
6、所有作品仅供您个人学习、研究或欣赏,不得用于商业或者其他用途,否则,一切后果均由您自己承担,我们对此不承担任何法律责任
7、如涉及侵犯版权等问题,请您及时通知我们,我们将立即采取措施予以解决
8、联系人Email:admin@iyunv.com 网址:www.yunweiku.com