一、主机规划
本次实验利用五台CentOS7虚拟机,其中两台安装keepalived,两台作为安装httpd,提供web服务。
RS1 | 172.18.12.3 | httpd |
RS2 | 172.18.12. | http |
HA1 | 172.18.12.1 | keepalived |
HA2 | 172.18.12.11 | keepalived |
客户机 | 172.18.12.250.243 |
虚拟ip:172.18.12.234
为了尽量减少环境对实验的干扰,需关闭防火墙和selinux
二、HA主机设定
1. 安装keepalive和检查工具ipvsadm
# yum install keepalived -y # yum install -y ipvsadm
2.修改配置文件
# vim keepalived.conf
! Configuration File for keepalived global_defs { notification_email { root@dy.com } notification_email_from Rex@keadm smtp_server 127.0.0.1 smtp_connect_timeout 30 router_id LVS_DEVEL } vrrp_instance VI_1 { state MASTER interface eno16777736 virtual_router_id 51 priority 100 advert_int 1 authentication { auth_type PASS auth_pass 1111 } virtual_ipaddress { 172.18.12.234/16 } } virtual_server 172.18.12.234 80 { delay_loop 6 lb_algo rr lb_kind DR nat_mask 255.255.0.0 protocol TCP real_server 172.18.12.3 80 { weight 1 HTTP_GET { url { path / status_code 200 } connect_timeout 3 nb_get_retry 3 delay_before_retry 3 } } real_server 172.18.12.4 80 { weight 1 HTTP_GET { url { path / status_code 200 } connect_timeout 3 nb_get_retry 3 delay_before_retry 3 } } }
# systemctl restart keepalived.service
3.HA2备用路由器设定
! Configuration File for keepalived global_defs { notification_email { root@dy.com } notification_email_from Rex@keadm smtp_server 127.0.0.1 smtp_connect_timeout 30 router_id LVS_DEVEL } vrrp_instance VI_1 { state BACKUP interface eno16777736 virtual_router_id 51 priority 90 advert_int 1 authentication { auth_type PASS auth_pass 1111 } virtual_ipaddress { 172.18.12.234/16 } } virtual_server 172.18.12.234 80 { delay_loop 6 lb_algo rr lb_kind DR nat_mask 255.255.0.0 protocol TCP real_server 172.18.12.3 80 { weight 1 HTTP_GET { url { path / status_code 200 } connect_timeout 3 nb_get_retry 3 delay_before_retry 3 } } real_server 172.18.12.4 80 { weight 1 HTTP_GET { url { path / status_code 200 } connect_timeout 3 nb_get_retry 3 delay_before_retry 3 } } }
三、RS主机设置
# yum install httpd -y # vim /var/www/html/index.html
<h1> www.RS2.com</h1>
# vim nkc.sh
#!/bin/bash # VIP='172.18.12.234' case $1 in start) echo 1 > /proc/sys/net/ipv4/conf/all/arp_ignore echo 1 > /proc/sys/net/ipv4/conf/lo/arp_ignore echo 2 > /proc/sys/net/ipv4/conf/all/arp_announce echo 2 > /proc/sys/net/ipv4/conf/lo/arp_announce ;; stop) echo 0 > /proc/sys/net/ipv4/conf/all/arp_ignore echo 0 > /proc/sys/net/ipv4/conf/lo/arp_ignore echo 0 > /proc/sys/net/ipv4/conf/all/arp_announce echo 0 > /proc/sys/net/ipv4/conf/lo/arp_announce esac # ifconfig lo:0 $VIP netmask 255.255.255.255 broadcast $VIP route add -host $VIP dev lo:0
脚本说明:通过传参来实现对内核参数的控制,控制arp解析通告级别,以及设置虚拟ip,并由一条路由来指定,凡是经过172.18.12.234进来的主机我们都让其从io:0出去。注意必须限制通告级别再设置ip。
#bash vkc.sh start
[root@localhost ~]# ifconfig
eno16777736: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500 inet 172.18.253.86 netmask 255.255.0.0 broadcast 172.18.255.255 inet6 fe80::20c:29ff:fe3c:38be prefixlen 64 scopeid 0x20<link> ether 00:0c:29:3c:38:be txqueuelen 1000 (Ethernet) RX packets 115308 bytes 26442683 (25.2 MiB) RX errors 0 dropped 2 overruns 0 frame 0 TX packets 15460 bytes 1839145 (1.7 MiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536 inet 127.0.0.1 netmask 255.0.0.0 inet6 ::1 prefixlen 128 scopeid 0x10<host> loop txqueuelen 0 (Local Loopback) RX packets 166 bytes 15346 (14.9 KiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 166 bytes 15346 (14.9 KiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 lo:0: flags=73<UP,LOOPBACK,RUNNING> mtu 65536 inet 172.18.12.234 netmask 255.255.255.255 loop txqueuelen 0 (Local Loopback)
# systemctl start httpd
RS2设置同上
五、测试过程
1.启动从主机查看ipvs规则
# ipvsadm -Ln
IP Virtual Server version 1.2.1 (size=4096) Prot LocalAddress:Port Scheduler Flags -> RemoteAddress:Port Forward Weight ActiveConn InActConn TCP 172.18.12.234:80 rr -> 172.18.12.3:80 Route 1 0 0 -> 172.18.12.4:80 Route 1 0 0
可以发现,keepalived启动之后会自动加载配置文件中的集群服务规则