LVS小型系统架构搭建笔记

时间:2023-03-09 18:47:27
LVS小型系统架构搭建笔记

搭建环境说明

本次实现用到了6台节点,实现一个小型的Lvs负载调度

节点1客户端配置代表互联网用户

[root@centos7 network-scripts]# vi ifcfg-ens37 

TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=static
IPADDR=172.20.0.222
NETMASK=255.255.0.0
GATEWAY=172.20.0.80
DNS=172.20.127.159
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=ens37
UUID=d4341ea9-dfc5-4eb4-8f08-6349b7315cd8
DEVICE=ens37
ONBOOT=yes
PEERDNS=no

网卡配置

[root@centos7 network-scripts]# ip addr
: lo: <LOOPBACK,UP,LOWER_UP> mtu qdisc noqueue state UNKNOWN qlen
link/loopback ::::: brd :::::
inet 127.0.0.1/ scope host lo
valid_lft forever preferred_lft forever
inet6 ::/ scope host
valid_lft forever preferred_lft forever
: ens37: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu qdisc pfifo_fast state UP qlen
link/ether :0c::6e:7f:0b brd ff:ff:ff:ff:ff:ff
inet 172.20.0.222/ brd 172.20.255.255 scope global ens37
valid_lft forever preferred_lft forever
inet6 fe80:::eb6f:c485:527e/ scope link
valid_lft forever preferred_lft forever
: virbr0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu qdisc noqueue state DOWN qlen
link/ether :::e0:: brd ff:ff:ff:ff:ff:ff
inet 192.168.122.1/ brd 192.168.122.255 scope global virbr0
valid_lft forever preferred_lft forever
: virbr0-nic: <BROADCAST,MULTICAST> mtu qdisc pfifo_fast master virbr0 state DOWN qlen
link/ether :::e0:: brd ff:ff:ff:ff:ff:ff #路由配置
[root@centos7 network-scripts]# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 172.20.0.80 0.0.0.0 UG ens37
172.20.0.0 0.0.0.0 255.255.0.0 U ens37
192.168.122.0 0.0.0.0 255.255.255.0 U virbr0

路由和网络

[root@centos7 network-scripts]# cat /etc/resolv.conf
# Generated by NetworkManager
nameserver 172.20.127.159
[root@centos7 network-scripts]#

配置DNS

节点2DNS服务器

[root@localhost ~]# ip addr
: lo: <LOOPBACK,UP,LOWER_UP> mtu qdisc noqueue state UNKNOWN qlen
link/loopback ::::: brd :::::
inet 127.0.0.1/ scope host lo
valid_lft forever preferred_lft forever
inet6 ::/ scope host
valid_lft forever preferred_lft forever
: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu qdisc pfifo_fast state UP qlen
link/ether :0c::f6::d2 brd ff:ff:ff:ff:ff:ff
inet 172.20.127.159/ brd 172.20.255.255 scope global dynamic ens33
valid_lft 77367sec preferred_lft 77367sec
inet 172.20.127.160/ brd 172.20.255.255 scope global secondary ens33
valid_lft forever preferred_lft forever
inet6 fe80::c4be:ccbf:ed3c:f146/ scope link
valid_lft forever preferred_lft forever
[root@localhost ~]# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 172.20.0.1 0.0.0.0 UG ens33
172.20.0.0 0.0.0.0 255.255.0.0 U ens33

网络和路由

[root@localhost network-scripts]# vi ifcfg-ens33

TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=dhcp
IPADDR=172.20.127.160
NETMASK=255.255.0.0
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=ens33
UUID=9eb578d3--478f-9f9f-8a75dc50b157
DEVICE=ens33
ONBOOT=yes

网卡配置

节点3路由器

[root@localhost network-scripts]# vi ifcfg-ens33

TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=static
IPADDR=172.20.0.80
NETMASK=255.255.0.0
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=ens33
DEVICE=ens33
ONBOOT=yes [root@localhost network-scripts]# vi ifcfg-ens37 TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=static
IPADDR=192.168.30.200
NETMASK=255.255.255.0
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=ens37
DEVICE=ens37
ONBOOT=yes

网卡配置

[root@localhost network-scripts]# ip addr
: lo: <LOOPBACK,UP,LOWER_UP> mtu qdisc noqueue state UNKNOWN qlen
link/loopback ::::: brd :::::
inet 127.0.0.1/ scope host lo
valid_lft forever preferred_lft forever
inet6 ::/ scope host
valid_lft forever preferred_lft forever
: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu qdisc pfifo_fast state UP qlen
link/ether :0c::3b:b5: brd ff:ff:ff:ff:ff:ff
inet 172.20.0.80/ brd 172.20.255.255 scope global ens33
valid_lft forever preferred_lft forever
inet6 fe80::fa59:9f2f:aa03:/ scope link
valid_lft forever preferred_lft forever
: ens37: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu qdisc pfifo_fast state UP qlen
link/ether :0c::3b:b5: brd ff:ff:ff:ff:ff:ff
inet 192.168.30.200/ brd 192.168.30.255 scope global ens37
valid_lft forever preferred_lft forever
inet 10.0.0.100/ scope global ens37
valid_lft forever preferred_lft forever
inet6 fe80::7c:88e7::b883/ scope link
valid_lft forever preferred_lft forever [root@localhost network-scripts]# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
10.0.0.0 10.0.0.200 255.255.255.255 UGH ens37
10.0.0.0 0.0.0.0 255.255.255.0 U ens37
172.20.0.0 0.0.0.0 255.255.0.0 U ens33
192.168.30.0 0.0.0.0 255.255.255.0 U ens37

路由表

开启路由包转发

echo "net.ipv4.ip_forward = 1" >> /etc/sysctl.conf

sysctl -p               ----加载,使得配置文件立即生效

节点4Lvs服务器

1.安装lvs客户端管理工具包

[root@localhost network-scripts]# yum install ipvsadm

[root@localhost network-scripts]# vi ifcfg-ens33

TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=static
IPADDR=192.168.30.7
NETMASK=255.255.255.0
GATEWAY=192.168.30.200
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=ens33
UUID=9eb578d3--478f-9f9f-8a75dc50b157
DEVICE=ens33
ONBOOT=yes [root@localhost network-scripts]# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 172.20.0.1 0.0.0.0 UG ens37
0.0.0.0 192.168.30.200 0.0.0.0 UG ens33
10.0.0.0 0.0.0.0 255.255.255.0 U ens37
172.20.0.0 0.0.0.0 255.255.0.0 U ens37
192.168.30.0 0.0.0.0 255.255.255.0 U ens33 [root@localhost network-scripts]# ip addr
: lo: <LOOPBACK,UP,LOWER_UP> mtu qdisc noqueue state UNKNOWN qlen
link/loopback ::::: brd :::::
inet 127.0.0.1/ scope host lo
valid_lft forever preferred_lft forever
inet6 ::/ scope host
valid_lft forever preferred_lft forever
: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu qdisc pfifo_fast state UP qlen
link/ether :0c::a6:8d:ce brd ff:ff:ff:ff:ff:ff
inet 192.168.30.7/ brd 192.168.30.255 scope global ens33
valid_lft forever preferred_lft forever
inet6 fe80:::d83b:6d7a:226d/ scope link
valid_lft forever preferred_lft forever
: ens37: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu qdisc pfifo_fast state UP qlen
link/ether :0c::a6:8d:d8 brd ff:ff:ff:ff:ff:ff
inet 172.20.127.175/ brd 172.20.255.255 scope global dynamic ens37
valid_lft 81555sec preferred_lft 81555sec
inet 10.0.0.200/ scope global ens37
valid_lft forever preferred_lft forever
inet6 fe80::80ef:9ba0::/ scope link
valid_lft forever preferred_lft forever

网卡配置和路由

[root@localhost network-scripts]# ipvsadm -A -t 10.0.0.200: -s rr
[root@localhost network-scripts]# ipvsadm -a -t 10.0.0.200: -r 192.168.30.17
[root@localhost network-scripts]# ipvsadm -a -t 10.0.0.200: -r 192.168.30.27
[root@localhost network-scripts]# ipvsadm -Ln
IP Virtual Server version 1.2. (size=)
Prot LocalAddress:Port Scheduler Flags
-> RemoteAddress:Port Forward Weight ActiveConn InActConn
TCP 10.0.0.200: rr
-> 192.168.30.17: Route
-> 192.168.30.27: Route

lvs设置命令

节点5webserver1

TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=static
IPADDR=192.168.30.17
NETMASK=255.255.255.0
GATEWAY=192.168.30.200
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=ens33
UUID=9eb578d3--478f-9f9f-8a75dc50b157
DEVICE=ens33
ONBOOT=yes [root@localhost html]# ip addr a 10.0.0.200/ dev ens33
[root@localhost html]# cd /proc/sys/net/ipv4/conf/all
[root@localhost all]# echo > arp_ignore
[root@localhost all]# echo > arp_announce

网络配置

节点6webserver2

TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=static
IPADDR=192.168.30.27
NETMASK=255.255.255.0
GATEWAY=192.168.30.200
DEFROUTE=yes
IPV4_FAILURE_FATAL=no
IPV6INIT=yes
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_ADDR_GEN_MODE=stable-privacy
NAME=ens33
UUID=9eb578d3--478f-9f9f-8a75dc50b157
DEVICE=ens33
ONBOOT=yes [root@localhost html]# ip addr a 10.0.0.200/ dev ens33
[root@localhost html]# cd /proc/sys/net/ipv4/conf/all
[root@localhost all]# echo > arp_ignore
[root@localhost all]# echo > arp_announce

网络配置

注意事项

IP地址每段的最大值是255,超过255的设置都不会生效
[root@centos7 ~]# ip addr a 10.0.0.100/ dev ens37
[root@centos7 ~]# ip addr del 10.0.0.100/ dev ens37 添加静态路由
ip route add 10.0.0.0/ via 10.0.0.100 dev ens37 给一个网卡添加多个IP地址 不能使用ifconfig查看
[root@localhost ]# ip addr 如果在ip配置文件里面配置的网关,需要重启网络服务才会生效
路由匹配和系统中路由表记录的顺序有关,当匹配到前一条记录的时候后面的记录不会再生效
#记录顺序1 不能访问外网
[root@localhost network-scripts]# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.168.30.200 0.0.0.0 UG ens33
0.0.0.0 172.20.0.1 0.0.0.0 UG
[root@localhost network-scripts]# ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) () bytes of data.
From 192.168.30.200 icmp_seq= Destination Net Unreachable #记录顺序2 能访问外网
[root@localhost network-scripts]# route del default gw 192.168.30.200
[root@localhost network-scripts]# systemctl restart network
[root@localhost network-scripts]# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 172.20.0.1 0.0.0.0 UG ens37
0.0.0.0 192.168.30.200 0.0.0.0 UG [root@localhost network-scripts]# ping www.baidu.com
PING www.a.shifen.com (61.135.169.125) () bytes of data.
bytes from 61.135.169.125 (61.135.169.125): icmp_seq= ttl= time=96.8 ms
From 172.20.127.96 (172.20.127.96) icmp_seq= Redirect Network(New nexthop: gateway (172.20.0.1))

最终效果

在节点1上进行测试

[root@centos7 ~]# curl www.tianhuang.com
<h1>天皇万岁,我是web1</h1>
[root@centos7 ~]# curl www.tianhuang.com
<h1>天皇万岁,我是web2</h1>
[root@centos7 ~]# curl www.tianhuang.com
<h1>天皇万岁,我是web1</h1>
[root@centos7 ~]# curl www.tianhuang.com
<h1>天皇万岁,我是web2</h1>
[root@centos7 ~]# curl www.tianhuang.com
<h1>天皇万岁,我是web1</h1>
[root@centos7 ~]# curl www.tianhuang.com
<h1>天皇万岁,我是web2</h1>
[root@centos7 ~]#